CVE-2026-40520: FreePBX API
High severity, CVSS 8.8. EPSS: 2.4% chance of exploitation in the next 30 days.
FreePBX api module version 17.0.8 and prior contain a command injection vulnerability in the initiateGqlAPIProcess() function where GraphQL mutation input fields are passed directly to shell_exec() without sanitization or escaping. An authenticated user with a valid bearer token can send a GraphQL moduleOperations mutation with backtick-wrapped commands in the module field to execute arbitrary commands on the underlying host as the web server user.
Affected products
- FreePBX API: before 17.0.8 (fixed in 17.0.8)
Published 2026-04-21. Last modified 2026-07-14.