Critical FreePBX Vulnerability Exposes User Portals to Attackers
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A critical vulnerability in FreePBX, tracked as CVE-2026-46376, allows unauthenticated attackers to access user portals via the User Control Panel (UCP). This flaw arises from hard-coded credentials in the userman module and affects FreePBX versions prior to 16.0.45 and 17.0.7. Systems running outdated versions are particularly at risk. The vulnerability has a CVSS v4 base score of 9.1, indicating its severity. Administrators are urged to update their systems to mitigate the risk. The issue was disclosed on May 20, 2026, with no reports of active exploitation at this time.
Key Points: • CVE-2026-46376 allows unauthenticated access to FreePBX user portals. • The vulnerability affects FreePBX versions before 16.0.45 and 17.0.7. • Administrators are advised to upgrade systems to prevent potential exploitation.