CVE-2026-45562
Last modified
CVE-2026-45562 is a high-severity vulnerability rated 7.7/10 on the CVSS scale. FreePBX is an open source IP PBX. Prior to versions 16.0.4 and 17.0.6, the FreePBX Music on Hold (MoH) module contains a critical security flaw that allows authenticated attackers to execute arbitrary system commands with the privileges of the Asterisk service.
Description
FreePBX is an open source IP PBX. Prior to versions 16.0.4 and 17.0.6, the FreePBX Music on Hold (MoH) module contains a critical security flaw that allows authenticated attackers to execute arbitrary system commands with the privileges of the Asterisk service. Authentication with an existing FreePBX administrator account is required. The root cause lies in the fact that the module accepts a POST parameter that defines a custom Asterisk application, which is then stored in the database without any sanitization. Later, this data is written directly to the musiconhold_additional.conf configuration file without validation. Since Asterisk reads this configuration file and executes the specified application, an attacker can inject arbitrary commands that will be executed with Asterisk's permissions. This issue has been patched in versions 16.0.4 and 17.0.6.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| FreePBX | security-reporting | < 16.0.4; < 17.0.6 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-45562?
How severe is CVE-2026-45562?
How do I fix CVE-2026-45562?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-45557Technitium DNS Server aggressively tries to fetch missing RR…6.9
- CVE-2026-45558Roxy-WI is a web interface for managing Haproxy, Nginx, Apac…9.9
- CVE-2026-45559Roxy-WI is a web interface for managing Haproxy, Nginx, Apac…4.9
- CVE-2026-4556Exam4 is affected by a local privilege escalation vulnerabil…7.8
- CVE-2026-45560Roxy-WI is a web interface for managing Haproxy, Nginx, Apac…6.1
- CVE-2026-45561Roxy-WI is a web interface for managing Haproxy, Nginx, Apac…6.5
- CVE-2026-45563Roxy-WI is a web interface for managing Haproxy, Nginx, Apac…4.3
- CVE-2026-45564Roxy-WI is a web interface for managing Haproxy, Nginx, Apac…8.8
- CVE-2026-45565Roxy-WI is a web interface for managing Haproxy, Nginx, Apac…8.1
- CVE-2026-45566Roxy-WI is a web interface for managing Haproxy, Nginx, Apac…6.1
- CVE-2026-45567Roxy-WI is a web interface for managing Haproxy, Nginx, Apac…8.3
- CVE-2026-45568zrok is software for sharing web services, files, and networ…9.1
Are you affected by CVE-2026-45562?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
