CVE-2026-73661: FreePBX: Authenticated Framework AUTHTYPE Can Be Restored From a Crafted Backup
FreePBX is an open source IP PBX. Prior to 16.0.47 and 17.0.30, the FreePBX Framework module permits a crafted backup to restore the hidden AUTHTYPE setting with the value none through runRestore() in ampconf/htdocs/admin/libraries/Builtin/Restore.php. An authenticated user with sufficient backup-restore access or write access to backup files can thereby disable FreePBX authentication during restoration, bypassing the user-interface removal of AUTHTYPE=none. This issue is fixed in versions 16.0.47 and 17.0.30.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
FreePBX Framework (FreePBX)to a version that resolves this vulnerability.Fixed in 16.0.47 - Upgrade
Upgrade
FreePBX Framework (FreePBX)to a version that resolves this vulnerability.Fixed in 17.0.30