Skip to content
ThreatCluster

FreePBX Vulnerabilities Enable Remote Code Execution via Authentication Bypass

First seen 16 Dec 2025, 19:56 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 12, 2026 at 13:27 UTC

FreePBX has addressed critical vulnerabilities in its Endpoint Manager module that allow for authentication bypass and remote code execution. Discovered by Horizon3.ai researchers, these vulnerabilities affect telephony endpoint configurations in the open-source IP PBX system and include three high-severity issues distinct from CVE-2025-57819. CVE-2025-66039 is one of the identified vulnerabilities that enables this exploit.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 182d ago How this analysis works

More articles in this cluster (2)

Following this threat?

Track CVE-2025-57819 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed