CVE-2026-28287

FreePBX is an open source IP PBX. From versions 16.0.17.2 to before 16.0.20 and from version 17.0.2.4 to before 17.0.5, multiple command injection vulnerabilities exist in the recordings module. This issue has been patched in versions 16.0.20 and 17.0.5.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sangoma:freepbx:*:*:*:*:*:*:*:*
cpe:2.3:a:sangoma:freepbx:*:*:*:*:*:*:*:*

History

06 Mar 2026, 17:55

Type Values Removed Values Added
References () https://github.com/FreePBX/security-reporting/security/advisories/GHSA-9vv6-h8v6-rp4q - () https://github.com/FreePBX/security-reporting/security/advisories/GHSA-9vv6-h8v6-rp4q - Mitigation, Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
First Time Sangoma freepbx
Sangoma
CPE cpe:2.3:a:sangoma:freepbx:*:*:*:*:*:*:*:*

05 Mar 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-05 19:16

Updated : 2026-03-06 17:55


NVD link : CVE-2026-28287

Mitre link : CVE-2026-28287

CVE.ORG link : CVE-2026-28287


JSON object : View

Products Affected

sangoma

  • freepbx
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')