CVE-2026-72578: FreePBX Framework

High severity, CVSS 8.8. EPSS: 0.3% chance of exploitation in the next 30 days.

A cross-site request forgery (CSRF) vulnerability in FreePBX Framework 17.0 allows an unauthenticated remote attacker to perform administrative actions on behalf of an authenticated administrator.

Affected products

  • FreePBX FreePBX Framework: version 17.0 only

Published 2026-08-10. Last modified 2026-08-28.