Skip to main content
Vulnerability Database/CVE-2026-54675

CVE-2026-54675: FreePBX File Upload RCE Vulnerability

CVE-2026-54675 is a remote code execution vulnerability in FreePBX allowing authenticated attackers to upload malicious files. This post covers the technical details, affected versions, security impact, and mitigation steps.

Published:

CVE-2026-54675 Overview

CVE-2026-54675 is a path traversal vulnerability [CWE-22] in FreePBX, an open-source IP PBX platform. The flaw resides in the sound language upload and conversion functionality. An authenticated attacker with a known username can write arbitrary files to the web server's document root. This results in remote code execution (RCE) through malicious PHP files. The vulnerability affects FreePBX versions prior to 16.0.10 and 17.0.5. Insufficient path sanitization during the file conversion process enables the traversal attack.

Critical Impact

Authenticated attackers can achieve remote code execution on FreePBX servers by writing malicious PHP files to the web root through path traversal in the sound conversion feature.

Affected Products

  • FreePBX versions prior to 16.0.10
  • FreePBX versions prior to 17.0.5
  • Sound language upload and conversion module

Discovery Timeline

  • 2026-09-28 - CVE-2026-54675 published to NVD
  • 2026-09-30 - Last updated in NVD database

Technical Details for CVE-2026-54675

Vulnerability Analysis

The vulnerability resides in the FreePBX sound language upload feature. During file upload and conversion, the application processes user-supplied filenames without adequate path validation. An authenticated user can craft filenames containing directory traversal sequences to escape the intended upload directory. The conversion routine then writes the resulting file to an attacker-controlled location within the web server's document root. Placing a PHP file in this location enables direct invocation via HTTP requests, resulting in code execution under the web server's user context.

Root Cause

The root cause is insufficient sanitization of file path components in the sound language conversion process. FreePBX did not canonicalize or reject traversal sequences such as ../ in destination paths. This falls under CWE-22: Improper Limitation of a Pathname to a Restricted Directory. Combined with the ability to write files with attacker-controlled content and extension, the flaw escalates from a file write primitive to full RCE.

Attack Vector

Exploitation requires network access to the FreePBX administrative interface and valid credentials for a known user account. The attacker uploads a specially crafted sound file with path traversal sequences in its metadata or filename. The conversion process writes the malicious PHP payload into the web root. The attacker then requests the file via HTTP to trigger execution. See the FreePBX Security Advisory GHSA-95gm-cmxf-cv8v for additional technical context.

Detection Methods for CVE-2026-54675

Indicators of Compromise

  • Unexpected .php files appearing in the FreePBX web root directory or its subdirectories
  • Access log entries showing HTTP requests to newly created PHP files with unusual names
  • Sound language upload requests containing ../ sequences or encoded traversal patterns in filename parameters
  • Web server processes spawning shell commands such as sh, bash, or nc shortly after admin panel uploads

Detection Strategies

  • Monitor the FreePBX web root and module directories for the creation of unauthorized PHP files
  • Inspect FreePBX audit logs for sound language upload activity from unexpected user accounts
  • Correlate authenticated admin sessions with subsequent file writes outside expected upload directories
  • Alert on HTTP POST requests to sound upload endpoints containing traversal sequences in multipart form data

Monitoring Recommendations

  • Enable and centralize FreePBX access and error logs for real-time analysis
  • Deploy file integrity monitoring (FIM) on the FreePBX document root and configuration directories
  • Track process execution chains where the web server user (asterisk or www-data) invokes system utilities
  • Review authentication logs for brute-force attempts against known FreePBX usernames

How to Mitigate CVE-2026-54675

Immediate Actions Required

  • Upgrade FreePBX to version 16.0.10, 17.0.5, or later without delay
  • Audit administrative user accounts and rotate credentials for any account that may have been exposed
  • Restrict network access to the FreePBX administrative interface using firewall rules or a VPN
  • Inspect the web root for unauthorized PHP files and remove any that cannot be verified as legitimate

Patch Information

The FreePBX maintainers addressed the vulnerability in versions 16.0.10 and 17.0.5. The patch implements path sanitization in the sound language upload and conversion routines, rejecting filenames containing traversal sequences. Administrators should apply the update through the standard FreePBX module admin interface or package manager. Refer to the GitHub Security Advisory GHSA-95gm-cmxf-cv8v for full remediation guidance.

Workarounds

  • Disable or restrict access to the sound language upload feature until patching is complete
  • Enforce strong, unique passwords and multi-factor authentication for all FreePBX administrator accounts
  • Place the FreePBX administrative interface behind a reverse proxy with IP allow-listing
  • Configure the web server to deny PHP execution in directories that store user-uploaded content
bash
# Configuration example: deny PHP execution in upload directories (Apache)
<Directory "/var/lib/asterisk/sounds">
    <FilesMatch "\.ph(p[3-7]?|tml)$">
        Require all denied
    </FilesMatch>
</Directory>

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.