Junglewise Threat Intelligence

CVE-2026-44239: FreePBX Dashboard module local file inclusion

CVE-2026-44239 · Severity: info · CVSS 7.6 · Published 2026-05-29

Vendors: FreePBX.

Executive brief

FreePBX is an open-source communication platform used for managing IP-based phone systems. A security flaw in the Dashboard module allows an authenticated user to execute malicious code on the server. This could lead to a full system takeover, unauthorized access to call records, or disruption of telecommunications services.

Technical details

A Local File Inclusion (LFI) vulnerability exists in the Dashboard module of FreePBX due to improper path sanitization in the getcontent AJAX handler. The 'rawname' parameter is concatenated into a PHP include() call with a '.class.php' suffix. An authenticated attacker can use directory traversal sequences (../) to include and execute arbitrary .class.php files from the local filesystem. Although the application may eventually throw a class instantiation error, the PHP code within the included file executes beforehand. This allows for remote code execution (RCE) under the privileges of the webserver user (typically 'asterisk'). The issue is resolved in versions 16.0.22 and 17.0.5.

Affected products

  • FreePBX Dashboard module < 16.0.22, < 17.0.5

Timeline

  • 2026-05-19: advisory: GitHub advisory GHSA-hw7v-v2jp-wc4v published
  • 2026-05-29: disclosed: CVE-2026-44239 published to NVD

References