CVE-2026-73664: FreePBX: Authenticated Arbitrary SSH Key Injection via Backup Module
FreePBX is an open source IP PBX. From 17.0.5.34 until 17.0.11, the publicKeySave AJAX endpoint in Backup.class.php accepts an authenticated administrator's SSH public key and appends it to /home/asterisk/.ssh/authorizedkeys for the asterisk system user without reliably enforcing backup-only command and source restrictions. The key grants persistent shell access that can execute arbitrary commands, access FreePBX and call data, modify system files, and disrupt services. This issue is fixed in version 17.0.11.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
FreePBXto a version that resolves this vulnerability.Fixed in 17.0.11
Event History
Frequently Asked Questions
What is the severity of CVE-2026-73664?
CVE-2026-73664 has a risk score of 68.
How do I fix CVE-2026-73664?
To mitigate CVE-2026-73664, upgrade FreePBX to version 17.0.11 or later.
What does CVE-2026-73664 exploit in FreePBX?
CVE-2026-73664 allows authenticated administrators to inject arbitrary SSH keys via the Backup Module.
Which versions of FreePBX are affected by CVE-2026-73664?
FreePBX versions from 17.0.5.34 to 17.0.10 are affected by CVE-2026-73664.
What potential impact does CVE-2026-73664 have on systems?
CVE-2026-73664 can lead to unauthorized access to the FreePBX system through injected SSH keys.