Disclosure summary
FreePBX is an open source IP PBX. From 17.0.1 until 17.0.7, the FreePBX Music on Hold module permits dangerous command-line options for /usr/bin/mpg123 and other allowed players in validateCustomConfiguration() in Music.class.php. An authenticated administrator can use options that write files, open control channels, or create Asterisk call files because applicationUsesDisallowedPlayerOption() does not reject those arguments, resulting in arbitrary command execution as the asterisk service user. This issue is fixed in version 17.0.7.
Source-reported weakness categories
CWE-78
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
NIST National Vulnerability Database · NVD-CVE-2026-73662
Open original source · Updated Oct 09, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
| Vendor | Product / association | Version / bounds |
|---|---|---|
| sangoma | freepbx | * {"versionStartIncluding":"17.0.1","versionEndExcluding":"17.0.7"} |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Patch
- github.com — Mitigation, Vendor Advisory
PUBLISHED 2026-08-13T18:17:27-04:00
MODIFIED 2026-10-09T15:32:16-04:00
INGESTED 2026-10-10T20:50:36-04:00