CVE-2026-73663
FreePBX: Unauthenticated SQL injection in FreePBX missedcall via inbound Caller ID name leads to administrator takeover
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
FreePBX is an open source IP PBX. From 16.0.0 until 16.0.11 and 17.0.4, the FreePBX missedcall module places the inbound Caller ID name from crafted SIP From headers into the missedcalllog INSERT in agi-bin/missedcallnotify.php without escaping or bound parameters. An unauthenticated caller can inject SQL when a monitored extension goes unanswered, corrupting the database and modifying FreePBX administrator accounts to obtain unauthorized remote access. This issue is fixed in versions 16.0.11 and 17.0.4.
| CWE | CWE-89 |
| Vendor | freepbx |
| Product | missedcall |
| Published | Aug 13, 2026 |
Stay Ahead of the Next One
Get instant alerts for freepbx missedcall
Be the first to know when new unknown vulnerabilities affecting freepbx missedcall are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
FreePBX / missedcall
< 16.0.11 >= 17.0.1, < 17.0.4