๐Ÿ” CVE Alert

CVE-2026-73663

UNKNOWN 0.0

FreePBX: Unauthenticated SQL injection in FreePBX missedcall via inbound Caller ID name leads to administrator takeover

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

FreePBX is an open source IP PBX. From 16.0.0 until 16.0.11 and 17.0.4, the FreePBX missedcall module places the inbound Caller ID name from crafted SIP From headers into the missedcalllog INSERT in agi-bin/missedcallnotify.php without escaping or bound parameters. An unauthenticated caller can inject SQL when a monitored extension goes unanswered, corrupting the database and modifying FreePBX administrator accounts to obtain unauthorized remote access. This issue is fixed in versions 16.0.11 and 17.0.4.

CWE CWE-89
Vendor freepbx
Product missedcall
Published Aug 13, 2026
Stay Ahead of the Next One

Get instant alerts for freepbx missedcall

Be the first to know when new unknown vulnerabilities affecting freepbx missedcall are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

FreePBX / missedcall
< 16.0.11 >= 17.0.1, < 17.0.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/FreePBX/security-reporting/security/advisories/GHSA-g27h-xf3q-h3rm github.com: https://github.com/FreePBX/missedcall/commit/4ada1d6b280fc246e74babc8d52f4cd1509eff24 github.com: https://github.com/FreePBX/missedcall/commit/710acdf51968db507b3f9c47ce3db006846cf44c