---
id: CVE-2026-45562
title: FreePBX is an open source IP PBX
summary: >-
  FreePBX is an open source IP PBX. Prior to versions 16.0.4 and 17.0.6, the
  FreePBX Music on Hold (MoH) module contains a critical security flaw that
  allows authenticated attackers to execute arbitrary system commands with the
  privileges …
severity: high
cvss: 7.7
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'
cwe:
  - CWE-78
vendor: FreePBX
product: security-reporting
affected:
  - security-reporting < 16.0.4
  - security-reporting < 17.0.6
published: '2026-09-28'
updated: '2026-09-28'
sourceUpdated: '2026-09-28T19:16:49.353'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-45562'
references:
  - url: >-
      https://github.com/FreePBX/security-reporting/security/advisories/GHSA-4g6v-whq9-944g
    label: security-advisories@github.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-28T18:36:57.131872Z'
cvssSource: cna
ingestedAt: '2026-09-28T18:17:54.309Z'
---

## Overview

FreePBX is an open source IP PBX. Prior to versions 16.0.4 and 17.0.6, the FreePBX Music on Hold (MoH) module contains a critical security flaw that allows authenticated attackers to execute arbitrary system commands with the privileges of the Asterisk service. Authentication with an existing FreePBX administrator account is required. The root cause lies in the fact that the module accepts a POST parameter that defines a custom Asterisk application, which is then stored in the database without any sanitization. Later, this data is written directly to the musiconhold_additional.conf configuration file without validation. Since Asterisk reads this configuration file and executes the specified application, an attacker can inject arbitrary commands that will be executed with Asterisk's permissions. This issue has been patched in versions 16.0.4 and 17.0.6.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
