Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4508 articles · 223849 vulns · 37/41 feeds (7d)
← Back to list
—
CVE-2026-73664
freepbx · backup

FreePBX: Authenticated Arbitrary SSH Key Injection via Backup Module

Description

FreePBX is an open source IP PBX. From 17.0.5.34 until 17.0.11, the publicKeySave AJAX endpoint in Backup.class.php accepts an authenticated administrator's SSH public key and appends it to /home/asterisk/.ssh/authorized_keys for the asterisk system user without reliably enforcing backup-only command and source restrictions. The key grants persistent shell access that can execute arbitrary commands, access FreePBX and call data, modify system files, and disrupt services. This issue is fixed in version 17.0.11.

Affected Products

VendorProductVersions
freepbxbackup>= 17.0.5.34, < 17.0.11

References

  • https://github.com/FreePBX/security-reporting/security/advisories/GHSA-24w6-hpg3-rwfg(x_refsource_CONFIRM)

Related News (1 articles)

Tier C
VulDB45d ago
CVE-2026-73664 | FreePBX up to 17.0.10 publicKeySave AJAX endpoint Backup.class.php improper authorization
→ No new info (linked only)

Discussion (0)

Loading…

CISA KEV❌ No
Actively exploited❌ No
CWECWE-269, CWE-284, CWE-732
PublishedAug 13, 2026
Trending Score0
Source articles1
Independent1
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-73660
FreePBX: Authenticated TTS AGI Command Injection Through TTS Name
NONECVE-2026-73662
Authenticated FreePBX Music RCE via mpg123 and Asterisk Call Files
NONECVE-2026-73661
FreePBX: Authenticated Framework AUTHTYPE Can Be Restored From a Crafted Backup
NONECVE-2026-73665
FreePBX UCP: Unauthenticated remote code execution via socket.io namespace auth bypass and AMI action injection
HIGHCVE-2026-72578
FreePBX Framework - Missing CSRF Protection in Admin Panel Ajax Dispatcher

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 13, 2026
Discovered by ZDM
Aug 13, 2026