Description
FreePBX is an open source IP PBX. Prior to 16.0.47 and 17.0.30, the FreePBX Framework module permits a crafted backup to restore the hidden AUTHTYPE setting with the value none through runRestore() in amp_conf/htdocs/admin/libraries/Builtin/Restore.php. An authenticated user with sufficient backup-restore access or write access to backup files can thereby disable FreePBX authentication during restoration, bypassing the user-interface removal of AUTHTYPE=none. This issue is fixed in versions 16.0.47 and 17.0.30.
Published: 2026-08-13
Score: 8.6 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

FreePBX Framework accepts a crafted backup file that can restore the hidden AUTHTYPE setting to the value none, effectively disabling authentication during the restore process. This flaw allows an authenticated user who can perform backup‑restore operations or write backup files to remove authentication and gain unrestricted access to the system. The vulnerability constitutes an incorrect access control weakness. The consequence is a loss of confidentiality, integrity, and availability for all users and services managed through FreePBX.

Affected Systems

The vulnerability affects the FreePBX Framework module on all releases prior to 16.0.47 and 17.0.30. An attacker must possess an authenticated session with backup‑restore privileges or write access to backup files to exploit it.

Risk and Exploitability

The CVSS score of 8.6 classifies this flaw as high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires authentication with sufficient backup privileges; an attacker can achieve the credential‑management bypass by submitting a malicious backup file during the restoration workflow.

Generated by OpenCVE AI on August 13, 2026 at 22:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade FreePBX Framework to version 16.0.47 or 17.0.30 where the issue is fixed
  • Restrict backup‑restore permissions to trusted administrators only
  • Audit existing backup files for authenticity and integrity before restoring

Generated by OpenCVE AI on August 13, 2026 at 22:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description FreePBX is an open source IP PBX. Prior to 16.0.47 and 17.0.30, the FreePBX Framework module permits a crafted backup to restore the hidden AUTHTYPE setting with the value none through runRestore() in amp_conf/htdocs/admin/libraries/Builtin/Restore.php. An authenticated user with sufficient backup-restore access or write access to backup files can thereby disable FreePBX authentication during restoration, bypassing the user-interface removal of AUTHTYPE=none. This issue is fixed in versions 16.0.47 and 17.0.30.
Title FreePBX: Authenticated Framework AUTHTYPE Can Be Restored From a Crafted Backup
Weaknesses CWE-15
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-08-13T21:28:16.031Z

Reserved: 2026-08-13T14:04:09.605Z

Link: CVE-2026-73661

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-13T22:17:27.627

Modified: 2026-08-13T22:17:27.627

Link: CVE-2026-73661

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T22:45:03Z

Weaknesses
  • CWE-15

    External Control of System or Configuration Setting