Executive brief
FreePBX is an open-source phone system used by businesses to manage their telecommunications. A security flaw in the User Control Panel (UCP) allows unauthorized individuals to log in using default, hard-coded credentials if an administrator has not manually changed them. This could allow an attacker to gain control over user settings and potentially intercept or disrupt communication services.
Technical details
A vulnerability in the FreePBX 'userman' module involves the use of hard-coded credentials (CWE-798) within the User Control Panel (UCP) generic template setup process. When an administrator enables UCP generic templates, the system utilizes static sample credentials that remain active unless manually rotated. A remote, unauthenticated attacker can use these known credentials to gain unauthorized access to the UCP interface. This allows for high impact on confidentiality and integrity of the user management system. The issue is resolved in versions 16.0.45 and 17.0.7 by randomizing these initial passwords.
Affected products
- FreePBX FreePBX userman module 15.0.42 to < 16.0.45, 17.0.x < 17.0.7
Timeline
- 2021: other: Vulnerability introduced into the codebase
- 2026-05-15: advisory: Vendor advisory published via GitHub
- 2026-05-29: disclosed: CVE published to NVD