CVE-2026-28284Disclosure(sangoma / freepbx)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch sangoma freepbx systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

FreePBX is an open source IP PBX. Prior to versions 16.0.10 and 17.0.5, the FreePBX logfiles module contains several authenticated SQL injection vulnerabilities. This issue has been patched in versions 16.0.10 and 17.0.5.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • freepbx

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 1 mentions (2026-03-05); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
freepbx

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-05: 1Mentions · 2026-03-06: 1Mentions · 2026-03-08: 1Patch / Workaround · 2026-03-05: 1Patch / Workaround · 2026-03-08: 1Technical Details · 2026-03-05: 1Technical Details · 2026-03-06: 1Technical Details · 2026-03-08: 103-0503-0603-08
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-28284 - High FreePBX is an open source IP PBX. Prior to versions 16.0.10 and 17.0.5, the FreePBX logfiles module contains several authenticated SQL injection vulnerabilities. This issue has been patched i... https://www.thehackerwire.com/vulnerability/CVE-2026-28284/ https://t.co/KFnRl93wXz

    Post summary

    A high‑severity authenticated SQL injection vulnerability (CVE‑2026‑28284) was disclosed in FreePBX modules prior to version 16.0.10/17.0.5 and the issue has been patched.

    0000041
    130 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-28284 Authenticated SQL Injection Vulnerabilities in FreePBX Logfiles Module https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-28284

    Post summary

    The text announces CVE-2026-28284, an authenticated SQL injection flaw in FreePBX Logfiles Module, without providing exploit code, patch information, or evidence of active exploitation.

    0000057
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-28284 FreePBX is an open source IP PBX. Prior to versions 16.0.10 and 17.0.5, the FreePBX logfiles module contains several authenticated SQL injection vulnerabilities. This… https://www.cve.org/CVERecord?id=CVE-2026-28284

    Post summary

    The text announces authenticated SQL injection flaws in the FreePBX logfiles module, noting that later releases (>=16.0.10 and >=17.0.5) contain the fix; no PoC, exploit, or active exploitation is mentioned.

    0000096
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsangomafreepbx---

Explore more