Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-73663: FreePBX: Unauthenticated SQL Injection via Caller ID

CVE-2026-73663 · published 1 month ago
Summary

FreePBX's missed call module has a security flaw that allows an attacker to inject malicious SQL code. This could lead to unauthorized access to the system and potentially allow an attacker to take control of the FreePBX administrator accounts. To fix this issue, update to version 16.0.11 or 17.0.4.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
freepbx missedcall < 16.0.11
Original advisory text
FreePBX: Unauthenticated SQL injection in FreePBX missedcall via inbound Caller ID name leads to administrator takeover
FreePBX is an open source IP PBX. From 16.0.0 until 16.0.11 and 17.0.4, the FreePBX missedcall module places the inbound Caller ID name from crafted SIP From headers into the missedcalllog INSERT in agi-bin/missedcallnotify.php without escaping or bound parameters. An unauthenticated caller can inject SQL when a monitored extension goes unanswered, corrupting the database and modifying FreePBX administrator accounts to obtain unauthorized remote access. This issue is fixed in versions 16.0.11 and 17.0.4.
Severity
9.9 Critical
CVSS 4.0: 9.3 (NVD)
CVSS 4.0: 9.9 (OSV)
Exploitation
EPSS 2%
Type
CWE-89SQL Injection
Timeline
Published13 Aug 2026
Updated25 Sep 2026
First seen13 Aug 2026
Sources
CVE-2026-73663 · MITRE
Track software like this
Free during beta