Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4356 articles · 196341 vulns · 36/41 feeds (7d)
← Back to list
—
CVE-2026-73663
FreePBX · missedcall

FreePBX: Unauthenticated SQL injection in FreePBX missedcall via inbound Caller ID name leads to administrator takeover

Description

FreePBX is an open source IP PBX. From 16.0.0 until 16.0.11 and 17.0.4, the FreePBX missedcall module places the inbound Caller ID name from crafted SIP From headers into the missedcalllog INSERT in agi-bin/missedcallnotify.php without escaping or bound parameters. An unauthenticated caller can inject SQL when a monitored extension goes unanswered, corrupting the database and modifying FreePBX administrator accounts to obtain unauthorized remote access. This issue is fixed in versions 16.0.11 and 17.0.4.

Affected Products

VendorProductVersions
FreePBXmissedcall< 16.0.11, >= 17.0.1, < 17.0.4

References

  • https://github.com/FreePBX/security-reporting/security/advisories/GHSA-g27h-xf3q-h3rm(x_refsource_CONFIRM)
  • https://github.com/FreePBX/missedcall/commit/4ada1d6b280fc246e74babc8d52f4cd1509eff24(x_refsource_MISC)
  • https://github.com/FreePBX/missedcall/commit/710acdf51968db507b3f9c47ce3db006846cf44c(x_refsource_MISC)

Related News (1 articles)

Tier C
VulDB10d ago
CVE-2026-73663 | FreePBX up to 16.0.10/17.0.3 missedcall module missedcallnotify.php sql injection
→ No new info (linked only)
CISA KEV❌ No
Actively exploited❌ No
CWECWE-89
PublishedAug 13, 2026
Last enriched10d ago
Trending Score4
Source articles1
Independent1
Info Completeness7/14
Missing: cvss, epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-73665
FreePBX UCP: Unauthenticated remote code execution via socket.io namespace auth bypass and AMI action injection
Trending: 10
HIGHCVE-2026-72578
FreePBX Framework - Missing CSRF Protection in Admin Panel Ajax Dispatcher
Trending: 6
NONECVE-2026-73662
Authenticated FreePBX Music RCE via mpg123 and Asterisk Call Files
Trending: 6
NONECVE-2026-73660
FreePBX: Authenticated TTS AGI Command Injection Through TTS Name
Trending: 6
NONECVE-2026-73664
FreePBX: Authenticated Arbitrary SSH Key Injection via Backup Module
Trending: 4

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 13, 2026
Discovered by ZDM
Aug 13, 2026