Junglewise Threat Intelligence

CVE-2026-72578: FreePBX Framework CSRF vulnerability in admin interface

CVE-2026-72578 · Severity: high · CVSS 8.8 · Published 2026-08-10

Vendors: FreePBX.

Executive brief

FreePBX Framework is the core module that provides administrative management for FreePBX telephone systems. A cross-site request forgery (CSRF) flaw in version 17.0 allows an attacker to trick a logged-in administrator into performing unintended administrative actions, such as modifying system settings, creating accounts, or disabling security features—without the administrator's knowledge or consent.

Technical details

The vulnerability is a classic cross-site request forgery (CSRF) in the FreePBX Framework version 17.0, specifically affecting the admin interface and AJAX handler components (Ajax.class.php). An unauthenticated remote attacker can craft a malicious webpage or email that, when visited by an authenticated FreePBX administrator, will trigger unauthorized administrative operations on the target FreePBX system. The attack exploits insufficient CSRF token validation or missing token verification in state-changing operations. No user interaction beyond clicking a link is required from the administrator's perspective. A patch or mitigation is expected from the FreePBX security team; apply updates when available.

Affected products

  • FreePBX Framework 17.0

Timeline

  • 2026-08-10: disclosed

References