Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4355 articles · 196337 vulns · 36/41 feeds (7d)
← Back to list
8.8
CVE-2026-72578
FreePBX · FreePBX Framework

FreePBX Framework - Missing CSRF Protection in Admin Panel Ajax Dispatcher

Description

A cross-site request forgery (CSRF) vulnerability in FreePBX Framework 17.0 allows an unauthenticated remote attacker to perform administrative actions on behalf of an authenticated administrator.

Affected Products

VendorProductVersions
FreePBXFreePBX Framework17.0

References

  • https://github.com/FreePBX/framework(third-party-advisory)
  • https://github.com/FreePBX/framework/blob/release/17.0/amp_conf/htdocs/admin/libraries/BMO/Ajax.class.php(technical-description)

Related News (1 articles)

Tier C
VulDB13d ago
CVE-2026-72578 | FreePBX 17.0 Ajax Ajax.class.php cross-site request forgery
→ No new info (linked only)
CVSS 3.18.8 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
CWECWE-352
PublishedAug 10, 2026
Last enriched13d ago
Trending Score6
Source articles1
Independent1
Info Completeness8/14
Missing: epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-73665
FreePBX UCP: Unauthenticated remote code execution via socket.io namespace auth bypass and AMI action injection
Trending: 10
NONECVE-2026-73662
Authenticated FreePBX Music RCE via mpg123 and Asterisk Call Files
Trending: 6
NONECVE-2026-73660
FreePBX: Authenticated TTS AGI Command Injection Through TTS Name
Trending: 6
NONECVE-2026-73664
FreePBX: Authenticated Arbitrary SSH Key Injection via Backup Module
Trending: 4
NONECVE-2026-73663
FreePBX: Unauthenticated SQL injection in FreePBX missedcall via inbound Caller ID name leads to administrator takeover
Trending: 4

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 10, 2026
Discovered by ZDM
Aug 10, 2026