---
id: CVE-2026-46376
title: >-
  FreePBX: Unauthenticated Use of Hard-Coded Credentials Vulnerability in
  FreePBX UCP Interface
summary: >-
  FreePBX is an open source IP PBX. From 15.0.42 to before 16.0.45 and 17.0.7,
  unauthenticated users may be able to access the User Control Panel (UCP) using
  hard-coded initial template credentials if these were not immediately changed
  by …
severity: critical
cvss: 9.3
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'
cvssSource: cna
cwe:
  - CWE-798
vendor: FreePBX
product: security-reporting
affected:
  - 'security-reporting >= 15.0.42, < 16.0.45'
  - 'security-reporting >= 17.0.1, < 17.0.7'
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-05-29T13:59:51.362788Z'
exploitAvailable: true
published: '2026-05-29'
updated: '2026-09-28'
sourceUpdated: '2026-09-28T16:57:56.083Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-46376'
references:
  - url: >-
      https://github.com/FreePBX/security-reporting/security/advisories/GHSA-m55x-h47x-v3gx
    label: >-
      https://github.com/FreePBX/security-reporting/security/advisories/GHSA-m55x-h47x-v3gx
tags:
  - cve.org
  - exploit-available
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/portbuster1337/CVE-2026-46376'
  checkedAt: '2026-09-28T17:17:02.713Z'
ingestedAt: '2026-09-28T17:16:27.805Z'
---

## Overview

FreePBX is an open source IP PBX. From 15.0.42 to before 16.0.45 and 17.0.7, unauthenticated users may be able to access the User Control Panel (UCP) using hard-coded initial template credentials if these were not immediately changed by the Administrator who enabled UCP. Authenticated access to ACP is required for the initial setup of UCP generic templates, but after that, without further steps by the admin, unauthenticated users may be able to gain access. This vulnerability is fixed in 16.0.45 and 17.0.7.

## Affected

- `security-reporting >= 15.0.42, < 16.0.45`
- `security-reporting >= 17.0.1, < 17.0.7`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
