CVE-2026-28287: FreePBX: Authenticated Remote Code Execution via Recordings Module AJAX Endpoints
FreePBX is an open source IP PBX. From versions 16.0.17.2 to before 16.0.20 and from version 17.0.2.4 to before 17.0.5, multiple command injection vulnerabilities exist in the recordings module. This issue has been patched in versions 16.0.20 and 17.0.5.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28287?
CVE-2026-28287 is classified as a critical vulnerability allowing authenticated remote code execution.
How do I fix CVE-2026-28287?
To fix CVE-2026-28287, upgrade to FreePBX version 16.0.20 or later, or version 17.0.5 or later.
What is the impact of CVE-2026-28287?
CVE-2026-28287 can lead to unauthorized execution of arbitrary commands on the affected FreePBX system.
Which versions of FreePBX are affected by CVE-2026-28287?
FreePBX versions from 16.0.17.2 to 16.0.20 and from 17.0.2.4 to 17.0.5 are vulnerable to CVE-2026-28287.
How does CVE-2026-28287 exploit the FreePBX system?
CVE-2026-28287 exploits command injection vulnerabilities in the recordings module's AJAX endpoints.