CVE-2026-73662
Last modified
CVE-2026-73662 is a high-severity vulnerability rated 7.6/10 on the CVSS scale. FreePBX is an open source IP PBX. From 17.0.1 until 17.0.7, the FreePBX Music on Hold module permits dangerous command-line options for /usr/bin/mpg123 and other allowed players in validateCustomConfiguration() in Music.class.php. EPSS estimates a 0.66% chance of exploitation in the next 30 days.
Description
FreePBX is an open source IP PBX. From 17.0.1 until 17.0.7, the FreePBX Music on Hold module permits dangerous command-line options for /usr/bin/mpg123 and other allowed players in validateCustomConfiguration() in Music.class.php. An authenticated administrator can use options that write files, open control channels, or create Asterisk call files because applicationUsesDisallowedPlayerOption() does not reject those arguments, resulting in arbitrary command execution as the asterisk service user. This issue is fixed in version 17.0.7.
Metrics
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| FreePBX | music | < 17.0.7 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-73662?
How severe is CVE-2026-73662?
How do I fix CVE-2026-73662?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-73657Trigger.dev is a platform for building and deploying fully m…4.2
- CVE-2026-73658Trigger.dev is a platform for building and deploying fully m…8.2
- CVE-2026-73659Trigger.dev is the open-source platform for building AI work…8.1
- CVE-2026-7366IBM DataPower Gateway 11.0.0.0 through 11.0.0.1 and IBM Data…4.2
- CVE-2026-73660FreePBX is an open source IP PBX. Prior to 16.0.6 and 17.0.5…7.5
- CVE-2026-73661FreePBX is an open source IP PBX. Prior to 16.0.47 and 17.0.…8.6
- CVE-2026-73663FreePBX is an open source IP PBX. From 16.0.0 until 16.0.11 …9.3
- CVE-2026-73664FreePBX is an open source IP PBX. From 17.0.5.34 until 17.0.…8.6
- CVE-2026-73665FreePBX is an open source IP PBX. Prior to 17.0.9, the UCP N…9.3
- CVE-2026-73666OpenChoreo is a developer platform for Kubernetes. Prior to …8.2
- CVE-2026-73667OpenChoreo is a complete, open-source developer platform for…8.8
- CVE-2026-73669The Signify Philips Hue Bridge Pro firmware embeds a Mosquit…7.3
Are you affected by CVE-2026-73662?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
