Junglewise Threat Intelligence

CVE-2026-73665: FreePBX UCP remote code execution via Socket.IO namespace auth bypass

CVE-2026-73665 · Severity: info · CVSS 9.3 · Published 2026-08-13

Vendors: FreePBX.

Executive brief

FreePBX is an open-source phone system software that allows organizations to manage voice, video, and messaging communications. The UCP (User Control Panel) Node server, which typically runs on ports 8001 and 8003, fails to properly authenticate connections to custom Socket.IO namespaces, allowing unauthenticated attackers to inject commands through the Asterisk Manager Interface and execute arbitrary code as the asterisk system user. An internet-facing FreePBX system without adequate firewall protection is at immediate risk of complete compromise.

Technical details

This vulnerability is a combination of two issues: a Socket.IO v4 middleware bypass and an Asterisk Manager Interface (AMI) command injection. The checkAuth middleware in node/lib/server.js uses io.use() which, in Socket.IO version 4, only applies to the default namespace—custom namespaces do not inherit this protection. An unauthenticated attacker can connect to these custom namespaces and call methods that forward user-supplied input to the AMI action path. By crafting events containing carriage-return (\r) or newline (\n) characters, the attacker bypasses AMI input validation and injects arbitrary Asterisk commands. The attack requires network access to the UCP ports (8001/8003) but no authentication or user interaction. The vulnerability affects all FreePBX 17 versions prior to 17.0.9 and is patched in 17.0.9.

Affected products

  • FreePBX FreePBX 17.0.0 to 17.0.8

Timeline

  • 2026-07-16: disclosed: GitHub Security Advisory GHSA-37j8-fhxx-9vhp published
  • 2026-07-16: patched: FreePBX version 17.0.9 released with fix
  • 2026-08-13: advisory: CVE-2026-73665 published on NVD

References