Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4358 articles · 196341 vulns · 36/41 feeds (7d)
← Back to list
—
CVE-2026-73662
FreePBX · music

Authenticated FreePBX Music RCE via mpg123 and Asterisk Call Files

Description

FreePBX is an open source IP PBX. From 17.0.1 until 17.0.7, the FreePBX Music on Hold module permits dangerous command-line options for /usr/bin/mpg123 and other allowed players in validateCustomConfiguration() in Music.class.php. An authenticated administrator can use options that write files, open control channels, or create Asterisk call files because applicationUsesDisallowedPlayerOption() does not reject those arguments, resulting in arbitrary command execution as the asterisk service user. This issue is fixed in version 17.0.7.

Affected Products

VendorProductVersions
FreePBXmusic< 17.0.7

References

  • https://github.com/FreePBX/security-reporting/security/advisories/GHSA-p97w-rq48-p8q2(x_refsource_CONFIRM)
  • https://github.com/FreePBX/music/commit/9f45605982202a34244ff22c4f635af0dfc1a733(x_refsource_MISC)

Related News (1 articles)

Tier C
VulDB10d ago
CVE-2026-73662 | FreePBX up to 17.0.6 Music on Hold Music.class.php validateCustomConfiguration os command injection
→ No new info (linked only)
CISA KEV❌ No
Actively exploited❌ No
CWECWE-78
PublishedAug 13, 2026
Last enriched10d ago
Trending Score6
Source articles1
Independent1
Info Completeness7/14
Missing: cvss, epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-73665
FreePBX UCP: Unauthenticated remote code execution via socket.io namespace auth bypass and AMI action injection
Trending: 10
HIGHCVE-2026-72578
FreePBX Framework - Missing CSRF Protection in Admin Panel Ajax Dispatcher
Trending: 6
NONECVE-2026-73660
FreePBX: Authenticated TTS AGI Command Injection Through TTS Name
Trending: 6
NONECVE-2026-73664
FreePBX: Authenticated Arbitrary SSH Key Injection via Backup Module
Trending: 4
NONECVE-2026-73663
FreePBX: Unauthenticated SQL injection in FreePBX missedcall via inbound Caller ID name leads to administrator takeover
Trending: 4

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 13, 2026
Discovered by ZDM
Aug 13, 2026