Threat intelligence dashboard
CVE-2026-45562high

FreePBX: Authenticated Remote Code Execution in FreePBX Music on Hold (MoH) Module

FreePBX is an open source IP PBX. Prior to versions 16.0.4 and 17.0.6, the FreePBX Music on Hold (MoH) module contains a critical security flaw that allows authenticated attackers to execute arbitrary system commands with the privileges of the Asterisk service. Authentication with an existing FreePBX administrator account is required. The root cause lies in the fact that the module accepts a POST parameter that defines a custom Asterisk application, which is then stored in the database without any sanitization. Later, this data is written directly to the musiconhold_additional.conf configuration file without validation. Since Asterisk reads this configuration file and executes the specified application, an attacker can inject arbitrary commands that will be executed with Asterisk's permissions. This issue has been patched in versions 16.0.4 and 17.0.6.

Risk score

7.7

CVSS 4.0

Vendor
FreePBX
Product
security-reporting
CWE
CWE-78
Published
Sep 28, 2026
Updated
Sep 28, 2026
CISA KEV
Not flagged

Affected products and versions

security-reporting

FreePBX

Version / rangeStatusType
< 16.0.4affected—
< 17.0.6affected—

Technical metrics

7.7

CVSS 4.0

Severity
high
Source
GitHub_M
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N