CVE-2026-73660
FreePBX: Authenticated TTS AGI Command Injection Through TTS Name
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
FreePBX is an open source IP PBX. Prior to 16.0.6 and 17.0.5.4, the FreePBX Text-To-Speech module allows an authenticated administrator to save a TTS destination name that is HTML-encoded for storage, decoded during dialplan generation, passed as an AGI argument, and used to build filenames inside agi-bin/propolys-tts.agi. The TTS destination name reaches a raw shell-command execution path, allowing arbitrary operating-system command execution as the asterisk service user. This issue is fixed in versions 16.0.6 and 17.0.5.4.
| CWE | CWE-78 |
| Vendor | freepbx |
| Product | tts |
| Published | Aug 13, 2026 |
| Last Updated | Aug 13, 2026 |
Stay Ahead of the Next One
Get instant alerts for freepbx tts
Be the first to know when new unknown vulnerabilities affecting freepbx tts are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
FreePBX / tts
< 16.0.6 >= 17.0.1, < 17.0.5.4