CVE-2026-44239: Sangoma FreePBX

High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.

FreePBX is an open source IP PBX. Prior to 16.0.22 and 17.0.5, the Dashboard module's getcontent AJAX handler includes PHP files based on user-supplied input without path sanitization. The $_REQUEST['rawname'] parameter is concatenated into an include() call with a .class.php suffix, allowing path traversal via ../ sequences to include arbitrary .class.php files from the filesystem. The included file's PHP code executes before the subsequent class instantiation error occurs. This vulnerability is fixed in 16.0.22 and 17.0.5.

Affected products

  • Sangoma FreePBX: before 16.0.22 (fixed in 16.0.22); from 17.0, before 17.0.5 (fixed in 17.0.5)

Published 2026-05-29. Last modified 2026-07-21.