Cyber Security News

FreePBX Vulnerability Allow Attackers to Gain Access to User Portals

A critical vulnerability in the open-source IP PBX platform FreePBX could allow unauthenticated attackers to access user portals.

The issue, tracked as CVE-2026-46376, affects the User Control Panel (UCP) interface due to hard-coded credentials in the userman module.

It impacts FreePBX versions before 16.0.45 and 17.0.7. Systems running outdated versions are at risk if administrators have not properly modified default credentials during initial configuration.

FreePBX Vulnerability

The flaw stems from the use of hard-coded sample credentials embedded in the UCP generic template during the setup process.

Although optional and designed to simplify deployment, this setup can create a serious security risk if administrators do not change the default credentials after initialization.

Once the template is configured, these credentials may remain active, allowing unauthenticated users to log in to the UCP without valid authentication.

Notably, attackers do not need prior access, privileges, or user interaction to exploit this issue, making it highly dangerous in exposed environments.

The vulnerability is categorized under CWE-798 (Use of Hard-coded Credentials), a well-known weakness that often leads to unauthorized access.

The vulnerability has been assigned a CVSS v4 base score of 9.1 (Critical), indicating a high level of risk.

The attack vector is network-based and low-complexity, and exploitation does not require authentication.

Successful exploitation could lead to:

While the vulnerability does not directly affect system availability, its impact on confidentiality and integrity is rated high.

The vulnerability was publicly disclosed under advisory GHSA-m55x-h47x-v3gx by security researcher chrsmj.

FreePBX developers have released patches to address the issue. Administrators are strongly advised to upgrade immediately:

  • FreePBX 16 users should update to version 16.0.45 or later.
  • FreePBX 17 users should update to version 17.0.7 or later.

Additional security measures include:

  • Ensuring all default or template credentials are changed during setup.
  • Restricting access to the Administrator Control Panel (ACP) using VPN, MFA, or SAML.
  • Using the FreePBX Firewall module to limit UCP and ACP access to trusted IP addresses.
  • Blocking access from untrusted or hostile networks.

Organizations should also audit existing deployments to identify systems where UCP templates were enabled without credential changes.

The vulnerability stemmed from a code change introduced in 2021 and was reported by researcher s0nnyWT, coordinated by chrsmj, with remediation developed by Sangoma.

Given its ease of exploitation and high impact, this vulnerability underscores the ongoing risks posed by insecure default configurations. It underscores the need for strict credential management practices in enterprise systems.

Follow us on Google NewsLinkedIn, and X to Get More Instant Updates.

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

3 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

13 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

14 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

14 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

14 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

15 hours ago