CVE-2026-54675: FreePBX: Authenticated Remote Code Execution via File Upload and Convert in Soundlang Module
FreePBX is an open source IP PBX. Prior to versions 16.0.10 and 17.0.5, a critical vulnerability exists in the sound language upload and conversion functionality that allows an authenticated attacker to perform arbitrary file writes, leading directly to remote code execution (RCE). Authentication with a known username is required. The vulnerability stems from insufficient path sanitization in the file conversion process, enabling path traversal attacks that place malicious PHP files in the web server's root directory. This issue has been patched in versions 16.0.10 and 17.0.5.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
FreePBXto a version that resolves this vulnerability.Fixed in 16.0.10 - Upgrade
Upgrade
FreePBXto a version that resolves this vulnerability.Fixed in 17.0.5
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The attacker must authenticate with a known FreePBX username. The available information does not state that administrative privileges are required.
Which deployments are affected?
FreePBX versions earlier than 16.0.10 and 17.0.5 are affected. The issue is in the sound language upload and conversion functionality.
What is the practical impact after successful exploitation?
An authenticated attacker can use path traversal during file conversion to write arbitrary files, including malicious PHP files in the web server root. This can directly result in remote code execution.
What remediation is available?
Upgrade FreePBX 16 installations to 16.0.10 or later, or FreePBX 17 installations to 17.0.5 or later. These versions contain the patch.