CVE-2026-26978Disclosure

LOWCVSS 8.6 · HIGH

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

FreePBX is an open source IP PBX. In versions below 16.0.71 and 17.0.6, the backup module does not properly sanitize data during restore operations, potentially leading to compromise if the backup contains carefully crafted hostile data. During backup restore operations, FreePBX extracts selected files from a user-supplied tar archive. If a malicious file exists in the archive, it is read and passed directly to unserialize() without validation, class restrictions, or integrity checks. This issue allows Remote Code Execution during restoration of the backup as the web server user (typically asterisk or www-data). The attack does not require shell access, CLI access, or filesystem write permissions beyond the normal restore workflow. Authentication with a known username that has sufficient access permissions and/or write access to backup files is required. This issue has been fixed in versions 16.0.71 and 17.0.6.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • 4 total mentions across 1 day

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-05-19: 4Patch / Workaround · 2026-05-19: 1Technical Details · 2026-05-19: 405-19
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets5 URLs
Full discourse4 posts
  • ADK Cyber@ADKCyber
    Patch

    FreePBX users: CVE-2026-26978 (CVSS 8.6) affects versions below 16.0.71 and 17.0.6 due to improper sanitization in the backup module. Update promptly to reduce risk. https://nvd.nist.gov/vuln/detail/CVE-2026-26978 Guidance at http://adkcyber.com via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability #AI #MachineLearning

    Post summary

    The post alerts FreePBX users to CVE-2026-26978, which affects versions below 16.0.71 and 17.0.6 due to improper sanitization in the backup module, and urges prompt updates, linking to NVD and guidance resources.

    0000051
    80 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-26978 FreePBX is an open source IP PBX. In versions below 16.0.71 and 17.0.6, the backup module does not properly sanitize data during restore operations, potentially leadi… https://www.cve.org/CVERecord?id=CVE-2026-26978 ----- Traducción: CVE-2026-26978 Fre… http://infoflow.cloud`

    Post summary

    CVE-2026-26978 has been disclosed for FreePBX, highlighting an unsanitized backup restore flaw in certain versions. No PoC, exploit code, active attacks, or patch details are mentioned.

    0000046
    78 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-26978 FreePBX is an open source IP PBX. In versions below 16.0.71 and 17.0.6, the backup module does not properly sanitize data during restore operations, potentially leadi… https://www.cve.org/CVERecord?id=CVE-2026-26978

    Post summary

    The text announces CVE‑2026‑26978, noting that FreePBX versions below 16.0.71 and 17.0.6 have a backup module that does not sanitize data during restores, creating a potential vulnerability.

    00000214
    57.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-26978 Remote Code Execution in FreePBX Backup Module via Unsafe Deserialization https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-26978

    Post summary

    The entry announces CVE‑2026‑26978 as a Remote Code Execution flaw in FreePBX’s backup module caused by unsafe deserialization, with no PoC, exploit, or patch disclosed.

    0000065
    4.0K followersView on X

Explore more