CVE-2026-26978
Last modified
CVE-2026-26978 is a high-severity vulnerability rated 8.6/10 on the CVSS scale. FreePBX is an open source IP PBX. In versions below 16.0.71 and 17.0.6, the backup module does not properly sanitize data during restore operations, potentially leading to compromise if the backup contains carefully crafted hostile data. EPSS estimates a 0.90% chance of exploitation in the next 30 days.
Description
FreePBX is an open source IP PBX. In versions below 16.0.71 and 17.0.6, the backup module does not properly sanitize data during restore operations, potentially leading to compromise if the backup contains carefully crafted hostile data. During backup restore operations, FreePBX extracts selected files from a user-supplied tar archive. If a malicious file exists in the archive, it is read and passed directly to unserialize() without validation, class restrictions, or integrity checks. This issue allows Remote Code Execution during restoration of the backup as the web server user (typically asterisk or www-data). The attack does not require shell access, CLI access, or filesystem write permissions beyond the normal restore workflow. Authentication with a known username that has sufficient access permissions and/or write access to backup files is required. This issue has been fixed in versions 16.0.71 and 17.0.6.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-26978?
How severe is CVE-2026-26978?
How do I fix CVE-2026-26978?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-2697An Indirect Object Reference (IDOR) in Security Center allow…8.8
- CVE-2026-26972OpenClaw is a personal AI assistant. In versions 2026.1.12 t…6.7
- CVE-2026-26973Discourse is an open source discussion platform. Versions pr…4.3
- CVE-2026-26974Slyde is a program that creates animated presentations from …9.8
- CVE-2026-26975Music Assistant is an open-source media library manager that…8.8
- CVE-2026-26977Frappe Learning Management System (LMS) is a learning system…5.3
- CVE-2026-26979Discourse is an open source discussion platform. Prior to ve…2.7
- CVE-2026-2698An improper access control vulnerability exists where an aut…6.5
- CVE-2026-26980Ghost is a Node.js content management system. Versions 3.24.…7.5
- CVE-2026-26981OpenEXR provides the specification and reference implementat…6.5
- CVE-2026-26982Ghostty is a cross-platform terminal emulator. Ghostty allow…8.8
- CVE-2026-26983ImageMagick is free and open-source software used for editin…5.3
Are you affected by CVE-2026-26978?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
