---
id: CVE-2026-54708
title: FreePBX is an open source IP PBX
summary: >-
  FreePBX is an open source IP PBX. Prior to versions 16.0.72 and 17.0.7, a
  critical vulnerability exists in the FreePBX backup Module that allows
  authenticated attackers to execute arbitrary code on the server.
  Authentication with a known…
severity: high
cvss: 8.6
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'
cwe:
  - CWE-22
  - CWE-94
vendor: FreePBX
product: security-reporting
affected:
  - security-reporting < 16.0.72
  - security-reporting < 17.0.7
published: '2026-09-28'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T04:17:56.490'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-54708'
references:
  - url: >-
      https://github.com/FreePBX/security-reporting/security/advisories/GHSA-5hhg-w366-g6fh
    label: security-advisories@github.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-28T00:00:00+00:00'
cvssSource: cna
ingestedAt: '2026-09-28T18:17:54.311Z'
---

## Overview

FreePBX is an open source IP PBX. Prior to versions 16.0.72 and 17.0.7, a critical vulnerability exists in the FreePBX backup Module that allows authenticated attackers to execute arbitrary code on the server. Authentication with a known username that has sufficient access permissions and/or write access to backup files is required. This vulnerability is caused by improper path sanitization in the backup restore functionality, enabling attackers to upload malicious PHP files to the web root directory. This issue has been patched in versions 16.0.72 and 17.0.7.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
