Executive brief
FreePBX is an open-source phone system that allows administrators to configure music played while callers are on hold. A flaw in the Music on Hold module allows authenticated administrators to inject dangerous command-line options into the music player (mpg123) that can execute arbitrary commands on the system with the privileges of the Asterisk service user, potentially compromising the entire phone system and accessing sensitive call data.
Technical details
The vulnerability is an improper input validation flaw in the FreePBX Music on Hold module's validateCustomConfiguration() function in Music.class.php. The applicationUsesDisallowedPlayerOption() validation function fails to reject dangerous command-line options (such as file write, control channel, or Asterisk call file creation flags) when configuring custom music players like /usr/bin/mpg123. An authenticated administrator with access to the FreePBX Admin Control Panel can inject these options to achieve arbitrary command execution as the asterisk service user. The vulnerability requires administrator-level authentication and is fixed in version 17.0.7 by implementing stricter argument allowlisting.
Affected products
- FreePBX Music on Hold module 17.0.1 to 17.0.6
Timeline
- 2026-07-16: disclosed: GitHub Security Advisory GHSA-p97w-rq48-p8q2 published
- 2026: patched: Fixed in version 17.0.7
- 2026-08-13: other: CVE-2026-73662 published to NVD