CVE-2026-46376 Details
Description
FreePBX is an open source IP PBX. From 15.0.42 to before 16.0.45 and 17.0.7, unauthenticated users may be able to access the User Control Panel (UCP) using hard-coded initial template credentials if these were not immediately changed by the Administrator who enabled UCP. Authenticated access to ACP is required for the initial setup of UCP generic templates, but after that, without further steps by the admin, unauthenticated users may be able to gain access. This vulnerability is fixed in 16.0.45 and 17.0.7.
A vulnerability exists in FreePBX versions 15.0.42 prior to 16.0.45 and 17.0.7, allowing unauthenticated users to access the User Control Panel (UCP) using hard-coded initial template credentials, unless these credentials were changed by an administrator. While authenticated access to the Administrator Control Panel (ACP) is required for the initial setup of UCP generic templates, once this setup is complete, unauthenticated users may gain access without further administrative intervention.
Users can update the 'userman' module to the latest version to randomize the password. It is also recommended to ensure that only authorized users have access to the FreePBX Administrator Control Panel, and to deny access from hostile networks to the ACP and UCP.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/FreePBX/security-reporting/security/advisories/GHSA-m55x-h47x-v3gx | [email protected] | MitigationVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-798 | Use of Hard-coded Credentials | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| sangoma freepbx | < 16.0.45 >= 17.0, < 17.0.7 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 21, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 1, 2026 | Initial Analysis | [email protected] |
| May 29, 2026 | New CVE Received | [email protected] |