CRITICAL 9.3 NVD
CVE-2026-73663
FreePBX is an open source IP PBX. From 16.0.0 until 16.0.11 and 17.0.4, the FreePBX missedcall module places the inbound Caller ID name from crafted SIP From he
FreePBX is an open source IP PBX. From 16.0.0 until 16.0.11 and 17.0.4, the FreePBX missedcall module places the inbound Caller ID name from crafted SIP From headers into the missedcalllog INSERT in agi-bin/missedcallnotify.php without escaping or bound parameters. An unauthenticated caller can inject SQL when a monitored extension goes unanswered, corrupting the database and modifying FreePBX administrator accounts to obtain unauthorized remote access. This issue is fixed in versions 16.0.11 and 17.0.4.
References
- https://github.com/FreePBX/missedcall/commit/4ada1d6b280fc246e74babc8d52f4cd1509eff24
- https://github.com/FreePBX/missedcall/commit/710acdf51968db507b3f9c47ce3db006846cf44c
- https://github.com/FreePBX/security-reporting/security/advisories/GHSA-g27h-xf3q-h3rm
This critical severity vulnerability with a CVSS score of 9.3 was published on 2026-08-13 via NVD.
Risk Timeline
CVE Disclosed2026-08-13 · 0 days ago
Remediation Resources
vulnfeed aggregates 11102 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.