CVE-2026-46376Disclosure(sangoma / freepbx)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch sangoma freepbx systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

FreePBX is an open source IP PBX. From 15.0.42 to before 16.0.45 and 17.0.7, unauthenticated users may be able to access the User Control Panel (UCP) using hard-coded initial template credentials if these were not immediately changed by the Administrator who enabled UCP. Authenticated access to ACP is required for the initial setup of UCP generic templates, but after that, without further steps by the admin, unauthenticated users may be able to gain access. This vulnerability is fixed in 16.0.45 and 17.0.7.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-798

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • freepbx

Threat summary

  • Patch or workaround signal is available
  • 10 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 8 signals
  • Disclosure: 5 classified signals
  • General: 2 classified signals
  • Peaked 5d ago at 4 mentions (2026-05-20); latest day: 1
  • 10 total mentions across 6 days

Affected systems

Vendors
Products
freepbx

Deep dive

Activity timeline10 mentions / 6d
01234Mentions · 2026-05-20: 4Mentions · 2026-05-21: 2Mentions · 2026-05-22: 1Mentions · 2026-05-27: 1Mentions · 2026-05-30: 1Mentions · 2026-06-01: 1Patch / Workaround · 2026-05-20: 2Patch / Workaround · 2026-05-30: 1Patch / Workaround · 2026-06-01: 1Technical Details · 2026-05-20: 3Technical Details · 2026-05-21: 1Technical Details · 2026-05-22: 1Technical Details · 2026-05-27: 1Technical Details · 2026-05-30: 1Technical Details · 2026-06-01: 105-2005-2105-2205-2705-3006-01
Signal classification3 categories
Disclosure
550.0%
Patch
330.0%
General
220.0%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-05-204
Disclosure1General1Patch2
2026-05-212
Disclosure1General1
2026-05-221
Disclosure1
2026-05-271
Disclosure1
2026-05-301
Patch1
2026-06-011
Disclosure1
Full discourse10 posts
  • FOFA@fofabot
    Disclosure

    ⚠️⚠️ CVE-2026-46376 (CVSS 9.1): FreePBX UCP generic template hardcoded creds enable portal access 🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJGcmVlUEJYIg%3D%3D 🎯47.1K+ Results are found on http://en.fofa.info in the past year. FOFA Query: app="FreePBX" 🔖Refer: https://securityonline.info/freepbx-ucp-vulnerability-cve-2026-46376-hardcoded-credentials/ #OSINT #FOFA #CyberSecurity #Vulnerability

    Post summary

    The post announces CVE‑2026‑46376, a high‑severity vulnerability in FreePBX UCP caused by hard‑coded credentials that grant portal access, and provides FOFA search results and a reference article for further details.

    1501962.4K
    14.4K followersView on X
  • elhacker.NET@elhackernet
    General

    Vulnerabilidad de FreePBX permite acceso a portales de usuario Se ha detectado una vulnerabilidad crítica (CVE-2026-46376) en la plataforma de código abierto FreePBX https://blog.elhacker.net/2026/05/vulnerabilidad-de-freepbx-permite.html

    Post summary

    The post announces a new critical vulnerability (CVE-2026-46376) in FreePBX but lacks detailed technical info, PoC, patch status, or evidence of exploitation, so stakeholders should consult additional sources for updates.

    0201151.4K
    141.0K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    FreePBX fixes critical 9.1 CVSS flaw (CVE-2026-46376) where hardcoded credentials grant unauthenticated portal access. Update your modules now! #FreePBX #VoIP #TelecomSecurity #CyberSecurity #InfoSec #Vulnerability #CVE #SysAdmin #Networking #PatchNow https://securityonline.info/freepbx-ucp-vulnerability-cve-2026-46376-hardcoded-credentials/

    Post summary

    The post announces that FreePBX has released a fix for CVE‑2026‑46376, a hardcoded credential flaw with a 9.1 CVSS score, and urges users to update their modules immediately.

    02081560
    12.5K followersView on X
  • CCB Alert@CCBalert
    Disclosure

    Warning: Critical vulnerability in #FreePBX. #CVE-2026-46376 CVSS: 9.1. Successful exploitation enables a remote unauthenticated attacker to gain access to the Control Panel. Read our advisory https://ccb.belgium.be/advisories/warning-critical-vulnerability-freepbx-allows-unauthenticated-attacker-gain-access. #Patch #Patch #Patch

    Post summary

    The post announces a critical CVE (CVE‑2026‑46376) in FreePBX, detailing remote unauthenticated access to the Control Panel, an advisory link with presumed patch information, and no mention of active exploitation or PoC.

    02000240
    7.2K followersView on X
  • Technology Updates@DIYprojects55
    Disclosure

    https://pbxscience.com/freepbx-user-management-hit-by-critical-hard-coded-credentials-flaw/ FreePBX User Management Hit by Critical Hard-Coded Credentials Flaw. A newly disclosed vulnerability — CVE-2026-46376 — allows unauthenticated attackers to gain portal access on FreePBX 16 and 17 systems where default credentials were never rotated..

    Post summary

    A new CVE (CVE-2026-46376) exposes FreePBX 16 and 17 to unauthenticated portal access through hard‑coded default credentials that were never rotated, highlighting a critical security flaw.

    0100176
    556 followersView on X
  • UNDERCODE NEWS@UndercodeNews
    General

    🚨 FreePBX Critical Userman Vulnerability (#CVE-2026-46376) Exposes Business Phone Systems to Unauthenticated Access -Fact Checker: ✅: 1 ❌: 0 || 1/1 http://undercodenews.com/freepbx-critical-userman-vulnerability-cve-2026-46376-exposes-business-phone-systems-to-unauthenticated-access/

    Post summary

    The tweet references a critical FreePBX CVE (CVE‑2026‑46376) concerning unauthenticated access, but it offers no additional technical details, patches, or exploitation claims.

    1001078
    861 followersView on X
  • yousukezan@yousukezan
    Patch

    FreePBXのUser Control Panel(UCP)で、認証不要アクセスを許す重大脆弱性CVE-2026-46376が修正された。初期設定時の固定テンプレート認証情報が原因で、外部攻撃者がVoIPシステムへ不正ログインできる状態になっていた。 問題はFreePBXのUCP generic template setup機能に存在する。この機能は大規模展開を容易にするためのテンプレート構成だが、初期状態でハードコード済みのサンプル認証情報を使用していた。管理者がテンプレート有効化後にパスワード変更を行わない場合、攻撃者は既知の認証情報だけでUCPへ直接ログインできる。 影響を受けるのはFreePBX 16系16.0.45未満、および17系17.0.7未満だ。CVSSは9.1で、侵害対象はユーザー向けポータルだが、組織ネットワーク内部への侵入口として悪用される危険がある。 開発元は修正版で、テンプレート用パスワードを自動ランダム化するよう変更した。管理者にはusermanモジュール更新に加え、Administrator Control Panel(ACP)へのアクセス制限、MFAやSAML導入、SysAdmin VPN利用が推奨されている。 さらにFreePBX Firewall機能を用い、UCPアクセスを登録済みSIP電話のIPアドレスのみに制限する設定も有効だとされる。インターネットからの直接公開は避けるべきだと警告されている。 https://securityonline.info/freepbx-ucp-vulnerability-cve-2026-46376-hardcoded-credentials/

    Post summary

    The post reports a critical vulnerability in FreePBX UCP involving hard‑coded credentials, details the impact and CVSS score, and specifies a patch plus recommended mitigations, but does not mention active exploitation or a PoC.

    000201.4K
    14.5K followersView on X
  • ADK Cyber@ADKCyber
    Patch

    CVE-2026-46376 (CVSS 9.3) impacts FreePBX 15.0.42–16.0.44 and 17.0.x before 17.0.7. Businesses using FreePBX should verify versions and apply updates to block unauthenticated UCP access. https://nvd.nist.gov/vuln/detail/CVE-2026-46376 via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability #AI #MachineLearning

    Post summary

    CVE-2026-46376 is a high‑severity vulnerability impacting specific FreePBX versions, with the primary notification urging users to verify their version and apply available updates to mitigate unauthenticated UCP access.

    0000038
    82 followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    FreePBX の脆弱性 CVE-2026-46376 が FIX:ユーザーポータルへの不正アクセスを招く恐れ https://iototsecnews.jp/2026/05/20/freepbx-security-flaw-lets-attackers-access-user-portals/ 今回の FreePBX の脆弱性 CVE-2026-46376 は、システムのセットアップ時にデプロイを簡単にする目的で用意されたテンプレート機能の中に、変更されずに残存するハードコードされた認証情報に起因します。初期設定の段階では認証が必要ですが、その後に、管理者による手動での設定変更やランダム値への更新が行われないと、ネットワーク経由で誰もがアクセスできる状態になってしまいます。開発時の利便性を重視した設計が、結果として未認証でのリモートアクセスを許すセキュリティ上の弱点へとつながっています。ご利用のチームは、ご注意ください。よろしければ、FreePBX での検索結果も、ご参照ください。 #CVE202646376 #FreePBX #Vulnerability

    Post summary

    The article announces the discovery of CVE‑2026‑46376 in FreePBX, highlighting its hard‑coded authentication flaw that can lead to unauthenticated remote access, but provides no evidence of exploitation or patch.

    0000086
    490 followersView on X
  • VulnTracker@vuln_tracker
    Disclosure

    Hardcoded credentials. In a phone system portal. CVSS 9.1. CVE-2026-46376 - FreePBX UCP ships with generic template hardcoded creds that grant portal access to anyone who knows them. 47,100+ exposed instances found online. Right now. Your PBX isn't just a phone. It's a foothold. http://vulntracker.io

    Post summary

    CVE-2026-46376 in FreePBX UCP exposes hardcoded credentials with a CVSS score of 9.1, affecting over 47,000 publicly accessible instances.

    00000187
    655 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsangomafreepbx---

Explore more