Junglewise Threat Intelligence

CVE-2026-40520: FreePBX api module command injection in initiateGqlAPIProcess

CVE-2026-40520 · Severity: high · CVSS 7.2 · Published 2026-04-21

Vendors: FreePBX.

Executive brief

FreePBX is an open-source graphical user interface that manages Asterisk, a popular voice-over-IP (VoIP) and telephony server. A security flaw in its API module allows an authorized user to execute malicious commands on the server. This could lead to a complete takeover of the phone system, allowing attackers to intercept calls, access sensitive data, or disrupt communications.

Technical details

A command injection vulnerability exists in the FreePBX 'api' module within the initiateGqlAPIProcess() function. The root cause is the direct passing of GraphQL mutation input fields to the PHP shell_exec() function without proper sanitization or escaping. An authenticated attacker with a valid bearer token can exploit this by sending a GraphQL 'moduleOperations' mutation containing backtick-wrapped shell commands in the 'module' field. Successful exploitation allows for arbitrary command execution on the underlying host with the privileges of the web server user. A patch has been identified in commit 5f194e3.

Affected products

  • FreePBX api module 17.0.8 and prior

Timeline

  • 2026-04-21: disclosed
  • 2026-04-21: advisory
  • 2026-04-21: patched: Patch commit 5f194e3 released

References

Related threats