CVE-2026-45562 Overview
CVE-2026-45562 is a command injection vulnerability [CWE-78] in the FreePBX Music on Hold (MoH) module. FreePBX is an open source IP PBX platform built on top of Asterisk. Authenticated administrators can inject arbitrary system commands that execute with the privileges of the Asterisk service. The module accepts a POST parameter defining a custom Asterisk application and stores the value in the database without sanitization. FreePBX later writes the value directly to musiconhold_additional.conf, which Asterisk parses and executes. Maintainers patched the flaw in versions 16.0.4 and 17.0.6.
Critical Impact
Authenticated FreePBX administrators can achieve arbitrary command execution on the PBX host as the Asterisk service user, enabling full compromise of voice infrastructure.
Affected Products
- FreePBX Music on Hold module versions prior to 16.0.4
- FreePBX Music on Hold module versions prior to 17.0.6
- Asterisk-based deployments using vulnerable FreePBX MoH configuration files
Discovery Timeline
- 2026-09-28 - CVE-2026-45562 published to NVD
- 2026-09-30 - Last updated in NVD database
Technical Details for CVE-2026-45562
Vulnerability Analysis
The FreePBX Music on Hold module exposes a POST parameter that defines a custom Asterisk application for MoH categories. The module writes user-supplied input to the database and then serializes it into musiconhold_additional.conf without validating or escaping the value. Asterisk reads this file, interprets the specified application, and executes it as part of normal call handling. An attacker with a valid administrator account can therefore turn a configuration write into command execution on the underlying host.
The Asterisk service typically runs with elevated privileges relative to the web interface, so successful exploitation grants code execution in a security-sensitive context. Compromise of the PBX exposes call recordings, SIP credentials, dial plans, and any integrated CRM or database backends.
Root Cause
The root cause is missing input validation and output encoding on a configuration value that is subsequently interpreted as executable content by Asterisk. The MoH module treats administrator-supplied data as trusted, and no sanitization boundary exists between the web form, the database, and the generated configuration file consumed by Asterisk.
Attack Vector
Exploitation requires network access to the FreePBX administrative interface and valid administrator credentials. The attacker submits a crafted POST request to the MoH module containing a malicious application string. Once written to musiconhold_additional.conf and reloaded by Asterisk, the payload executes with Asterisk service privileges. See the FreePBX Security Advisory GHSA-4g6v-whq9-944g for the technical details.
Detection Methods for CVE-2026-45562
Indicators of Compromise
- Unexpected entries in musiconhold_additional.conf containing shell metacharacters or references to unusual binaries
- Child processes of the Asterisk service that are not part of normal call handling, such as shells, curl, wget, or interpreters
- Outbound network connections initiated by the Asterisk process to unfamiliar hosts
- New or modified administrator accounts in the FreePBX web interface preceding configuration changes to MoH categories
Detection Strategies
- Monitor writes to musiconhold_additional.conf and diff generated configuration files against known-good baselines
- Correlate FreePBX administrator POST requests to the MoH module with subsequent Asterisk configuration reloads
- Alert on Asterisk spawning process trees inconsistent with SIP or dial plan execution
Monitoring Recommendations
- Forward FreePBX web server access logs and Asterisk process telemetry to a central SIEM for correlation
- Enable file integrity monitoring on /etc/asterisk/ and the FreePBX web root
- Track administrator authentication events and flag logins from unusual source addresses or outside business hours
How to Mitigate CVE-2026-45562
Immediate Actions Required
- Upgrade the FreePBX Music on Hold module to version 16.0.4 or 17.0.6, matching the installed FreePBX major release
- Audit musiconhold_additional.conf for suspicious application entries and revert unauthorized changes
- Rotate credentials for all FreePBX administrator accounts and review account inventory
- Restrict network access to the FreePBX administrative interface to trusted management networks
Patch Information
The FreePBX maintainers addressed the issue in Music on Hold module versions 16.0.4 and 17.0.6. Apply the update through the FreePBX Module Admin interface or via fwconsole ma upgrade musiconhold. Refer to the GitHub Security Advisory GHSA-4g6v-whq9-944g for the authoritative patch guidance.
Workarounds
- Disable the Music on Hold module until the patched version can be deployed if immediate patching is not possible
- Enforce multi-factor authentication and IP allowlisting on the FreePBX administrative interface to reduce the risk of credential abuse
- Run Asterisk under a least-privileged service account and apply mandatory access controls such as SELinux or AppArmor to limit the impact of code execution
# Example: upgrade the Music on Hold module via fwconsole
sudo fwconsole ma upgrade musiconhold
sudo fwconsole reload
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.