CVE-2026-75600 Overview
CVE-2026-75600 is an authenticated OS command injection vulnerability in FreePBX, an open source IP PBX platform. The flaw resides in the PBX API module's GraphQL documentation generator. It accepts an authenticated host parameter and passes it into a shell command without validation or escaping. Any authenticated user with access to the GraphQL api module interface can execute arbitrary shell commands as the FreePBX web/PBX service user, typically asterisk. The issue affects FreePBX versions prior to 17.0.9 and is tracked under [CWE-78] OS Command Injection.
Critical Impact
Authenticated attackers can execute arbitrary shell commands as the asterisk service account, leading to full compromise of telephony infrastructure and call data.
Affected Products
- FreePBX versions prior to 17.0.9
- FreePBX PBX API module (GraphQL interface)
- Deployments exposing the api module to authenticated users
Discovery Timeline
- 2026-09-28 - CVE-2026-75600 published to the National Vulnerability Database (NVD)
- 2026-09-30 - Last updated in NVD database
Technical Details for CVE-2026-75600
Vulnerability Analysis
The vulnerability exists in the FreePBX PBX API module's GraphQL documentation generator. The code path builds a shell command using the host parameter supplied by an authenticated caller. It validates the generated OAuth access token before executing the command but never validates or escapes the host value itself.
An attacker who holds valid credentials for the api module can inject shell metacharacters into host. The injected payload runs in the context of the FreePBX service user, typically asterisk. That account has broad access to PBX configuration, call recordings, dialplan logic, and SIP trunk credentials.
Exploitation does not require administrative privileges beyond api module access. Compromise of a single authenticated account is sufficient to achieve arbitrary command execution on the underlying host.
Root Cause
The root cause is missing input sanitization on a parameter that flows into a shell command. The developer added an authentication and token validation check but treated the host argument as trusted data. Shell metacharacters such as ;, |, `, and $() are passed through to the operating system shell without escaping.
Attack Vector
The attack vector is network-based and requires authenticated access to the GraphQL api module. An attacker crafts a GraphQL request that invokes the documentation generator with a malicious host value containing shell metacharacters. The FreePBX server executes the injected commands as the asterisk user. Refer to the FreePBX GitHub Security Advisory GHSA-79rg-3xp6-rqq6 for technical details.
Detection Methods for CVE-2026-75600
Indicators of Compromise
- Unexpected child processes spawned by the FreePBX web server or PHP-FPM under the asterisk user context.
- GraphQL API requests targeting the documentation generator with unusual characters in the host parameter such as ;, |, backticks, or $(.
- Outbound network connections from the PBX host to unfamiliar IP addresses shortly after api module authentication events.
- New cron entries, SSH keys, or files in /tmp or /var/spool/asterisk created by the asterisk account.
Detection Strategies
- Inspect web server access logs for GraphQL requests to the api module documentation endpoint containing shell metacharacters in query parameters.
- Monitor process ancestry on the PBX host for shell processes (sh, bash) spawned from PHP or web server processes.
- Correlate OAuth token issuance events with subsequent process execution anomalies on the FreePBX host.
Monitoring Recommendations
- Enable verbose logging on the FreePBX api module and forward logs to a centralized SIEM for retention and analysis.
- Alert on any execution of interpreters or network utilities such as curl, wget, nc, or python by the asterisk user outside of documented maintenance windows.
- Track baseline behavior of the FreePBX web tier and flag deviations in command execution patterns.
How to Mitigate CVE-2026-75600
Immediate Actions Required
- Upgrade FreePBX to version 17.0.9 or later, which contains the vendor patch.
- Restrict network access to the GraphQL api module interface to trusted management networks only.
- Rotate all api module credentials and OAuth client secrets in case of prior compromise.
- Audit accounts authorized to reach the api module and remove any that are unnecessary.
Patch Information
The FreePBX maintainers released a fix in version 17.0.9. Administrators should apply this update through the standard FreePBX module management workflow. Details are available in the FreePBX GitHub Security Advisory GHSA-79rg-3xp6-rqq6.
Workarounds
- Disable the PBX API module until the upgrade to 17.0.9 or later can be applied.
- Place the FreePBX management interface behind a VPN or IP allowlist to block untrusted access to the GraphQL endpoint.
- Enforce strong, unique credentials and multi-factor authentication for any account with api module access.
# Configuration example: restrict access to the FreePBX api module at the web tier
# Apache example - allow only trusted management subnet
<Location /admin/api>
Require ip 10.0.10.0/24
Require all denied
</Location>
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.