Impact
FreePBX Framework accepts a crafted backup file that can restore the hidden AUTHTYPE setting to the value none, effectively disabling authentication during the restore process. This flaw allows an authenticated user who can perform backup‑restore operations or write backup files to remove authentication and gain unrestricted access to the system. The vulnerability constitutes an incorrect access control weakness. The consequence is a loss of confidentiality, integrity, and availability for all users and services managed through FreePBX.
Affected Systems
The vulnerability affects the FreePBX Framework module on all releases prior to 16.0.47 and 17.0.30. An attacker must possess an authenticated session with backup‑restore privileges or write access to backup files to exploit it.
Risk and Exploitability
The CVSS score of 8.6 classifies this flaw as high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires authentication with sufficient backup privileges; an attacker can achieve the credential‑management bypass by submitting a malicious backup file during the restoration workflow.
OpenCVE Enrichment