CVE-2026-73664
Last modified
CVE-2026-73664 is a high-severity vulnerability rated 8.6/10 on the CVSS scale. FreePBX is an open source IP PBX. From 17.0.5.34 until 17.0.11, the publicKeySave AJAX endpoint in Backup.class.php accepts an authenticated administrator's SSH public key and appends it to /home/asterisk/.ssh/authorized_keys for the asterisk system user without reliably enforcing backup-only command and source restrictions. EPSS estimates a 0.65% chance of exploitation in the next 30 days.
Description
FreePBX is an open source IP PBX. From 17.0.5.34 until 17.0.11, the publicKeySave AJAX endpoint in Backup.class.php accepts an authenticated administrator's SSH public key and appends it to /home/asterisk/.ssh/authorized_keys for the asterisk system user without reliably enforcing backup-only command and source restrictions. The key grants persistent shell access that can execute arbitrary commands, access FreePBX and call data, modify system files, and disrupt services. This issue is fixed in version 17.0.11.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| FreePBX | backup | >= 17.0.5.34, < 17.0.11 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-73664?
How severe is CVE-2026-73664?
How do I fix CVE-2026-73664?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-73659Trigger.dev is the open-source platform for building AI work…8.1
- CVE-2026-7366IBM DataPower Gateway 11.0.0.0 through 11.0.0.1 and IBM Data…4.2
- CVE-2026-73660FreePBX is an open source IP PBX. Prior to 16.0.6 and 17.0.5…7.5
- CVE-2026-73661FreePBX is an open source IP PBX. Prior to 16.0.47 and 17.0.…8.6
- CVE-2026-73662FreePBX is an open source IP PBX. From 17.0.1 until 17.0.7, …7.6
- CVE-2026-73663FreePBX is an open source IP PBX. From 16.0.0 until 16.0.11 …9.3
- CVE-2026-73665FreePBX is an open source IP PBX. Prior to 17.0.9, the UCP N…9.3
- CVE-2026-73666OpenChoreo is a developer platform for Kubernetes. Prior to …8.2
- CVE-2026-73667OpenChoreo is a complete, open-source developer platform for…8.8
- CVE-2026-73669The Signify Philips Hue Bridge Pro firmware embeds a Mosquit…7.3
- CVE-2026-73670A CMS contains a SQL injection vulnerability in admin/db_dat…8.6
- CVE-2026-73671Saurus CMS Community Edition contains an unauthenticated ope…6.1
Are you affected by CVE-2026-73664?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
