Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-73663

FreePBX: Unauthenticated SQL injection in FreePBX missedcall via inbound Caller ID name leads to administrator takeover
Back to all
CVE

CVE-2026-73663

FreePBX: Unauthenticated SQL injection in FreePBX missedcall via inbound Caller ID name leads to administrator takeover

FreePBX is an open source IP PBX. From 16.0.0 until 16.0.11 and 17.0.4, the FreePBX missedcall module places the inbound Caller ID name from crafted SIP From headers into the missedcalllog INSERT in agi-bin/missedcallnotify.php without escaping or bound parameters. An unauthenticated caller can inject SQL when a monitored extension goes unanswered, corrupting the database and modifying FreePBX administrator accounts to obtain unauthorized remote access. This issue is fixed in versions 16.0.11 and 17.0.4.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.3
-
4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
C
H
U
0
-
C
H
U
-

Related Resources

No items found.

References

https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/73xxx/CVE-2026-73663.json, https://github.com/FreePBX/security-reporting/security/advisories/GHSA-g27h-xf3q-h3rm, https://nvd.nist.gov/vuln/detail/CVE-2026-73663, https://github.com/FreePBX/missedcall/commit/4ada1d6b280fc246e74babc8d52f4cd1509eff24, https://github.com/FreePBX/missedcall/commit/710acdf51968db507b3f9c47ce3db006846cf44c

Severity

0

CVSS Score
0
10

Basic Information

Base CVSS
0
EPSS Probability
0.00954%
EPSS Percentile
0.58778%
Introduced Version
20df0caf44ef637dbfbc4e440dd8bc84e4adab17
Fix Available
710acdf51968db507b3f9c47ce3db006846cf44c

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading