Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4358 articles · 196341 vulns · 36/41 feeds (7d)
← Back to list
—
CVE-2026-73665
freepbx · ucp

FreePBX UCP: Unauthenticated remote code execution via socket.io namespace auth bypass and AMI action injection

Description

FreePBX is an open source IP PBX. Prior to 17.0.9, the UCP Node server on ports 8001 and 8003 uses io.use(checkAuth) in node/lib/server.js, but Socket.IO version 4 applies that middleware only to the default namespace. An unauthenticated client can connect to custom namespaces that do not consistently invoke checkAuth in node/lib/auth.js and send crafted event values containing carriage-return or newline characters through the Asterisk Manager Interface action path patched by node/lib/asterisk-manager-patch.js, allowing arbitrary commands to execute as the asterisk service user. This issue is fixed in version 17.0.9.

Affected Products

VendorProductVersions
freepbxucp< 17.0.9

References

  • https://github.com/FreePBX/security-reporting/security/advisories/GHSA-37j8-fhxx-9vhp(x_refsource_CONFIRM)

Related News (1 articles)

Tier C
VulDB10d ago
CVE-2026-73665 | FreePBX up to 17.0.8 UCP Node Server node/lib/server.js checkAuth improper authentication
→ No new info (linked only)
CISA KEV❌ No
Actively exploited❌ No
CWECWE-862
PublishedAug 13, 2026
Trending Score10
Source articles1
Independent1
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-72578
FreePBX Framework - Missing CSRF Protection in Admin Panel Ajax Dispatcher
Trending: 6
NONECVE-2026-73662
Authenticated FreePBX Music RCE via mpg123 and Asterisk Call Files
Trending: 6
NONECVE-2026-73660
FreePBX: Authenticated TTS AGI Command Injection Through TTS Name
Trending: 6
NONECVE-2026-73664
FreePBX: Authenticated Arbitrary SSH Key Injection via Backup Module
Trending: 4
NONECVE-2026-73663
FreePBX: Unauthenticated SQL injection in FreePBX missedcall via inbound Caller ID name leads to administrator takeover
Trending: 4

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 13, 2026
Discovered by ZDM
Aug 13, 2026