๐Ÿ” CVE Alert

CVE-2026-73661

UNKNOWN 0.0

FreePBX: Authenticated Framework AUTHTYPE Can Be Restored From a Crafted Backup

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

FreePBX is an open source IP PBX. Prior to 16.0.47 and 17.0.30, the FreePBX Framework module permits a crafted backup to restore the hidden AUTHTYPE setting with the value none through runRestore() in amp_conf/htdocs/admin/libraries/Builtin/Restore.php. An authenticated user with sufficient backup-restore access or write access to backup files can thereby disable FreePBX authentication during restoration, bypassing the user-interface removal of AUTHTYPE=none. This issue is fixed in versions 16.0.47 and 17.0.30.

CWE CWE-15
Vendor freepbx
Product framework
Published Aug 13, 2026
Last Updated Aug 13, 2026
Stay Ahead of the Next One

Get instant alerts for freepbx framework

Be the first to know when new unknown vulnerabilities affecting freepbx framework are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

FreePBX / framework
< 16.0.47 >= 17.0.1, < 17.0.30

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/FreePBX/security-reporting/security/advisories/GHSA-f6hc-rqxg-ch86 github.com: https://github.com/FreePBX/framework/commit/0591581654bc269df05cbb7093645d6934d4d861 github.com: https://github.com/FreePBX/framework/commit/ea684be89abb393d1aff7f979d5fd751ff338dfd