A critical vulnerability in the open-source IP PBX platform FreePBX could allow unauthenticated attackers to access user portals.
The issue, tracked as CVE-2026-46376, affects the User Control Panel (UCP) interface due to hard-coded credentials in the userman module.
It impacts FreePBX versions before 16.0.45 and 17.0.7. Systems running outdated versions are at risk if administrators have not properly modified default credentials during initial configuration.
The flaw stems from the use of hard-coded sample credentials embedded in the UCP generic template during the setup process.
Although optional and designed to simplify deployment, this setup can create a serious security risk if administrators do not change the default credentials after initialization.
Once the template is configured, these credentials may remain active, allowing unauthenticated users to log in to the UCP without valid authentication.
Notably, attackers do not need prior access, privileges, or user interaction to exploit this issue, making it highly dangerous in exposed environments.
The vulnerability is categorized under CWE-798 (Use of Hard-coded Credentials), a well-known weakness that often leads to unauthorized access.
The vulnerability has been assigned a CVSS v4 base score of 9.1 (Critical), indicating a high level of risk.
The attack vector is network-based and low-complexity, and exploitation does not require authentication.
Successful exploitation could lead to:
While the vulnerability does not directly affect system availability, its impact on confidentiality and integrity is rated high.
The vulnerability was publicly disclosed under advisory GHSA-m55x-h47x-v3gx by security researcher chrsmj.
FreePBX developers have released patches to address the issue. Administrators are strongly advised to upgrade immediately:
Additional security measures include:
Organizations should also audit existing deployments to identify systems where UCP templates were enabled without credential changes.
The vulnerability stemmed from a code change introduced in 2021 and was reported by researcher s0nnyWT, coordinated by chrsmj, with remediation developed by Sangoma.
Given its ease of exploitation and high impact, this vulnerability underscores the ongoing risks posed by insecure default configurations. It underscores the need for strict credential management practices in enterprise systems.
Follow us on Google News, LinkedIn, and X to Get More Instant Updates.
Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…
The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…
CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…
Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…
You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…
Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…