FreePBX api module version 17.0.8 and prior contain a command injection vulnerability in the initiateGqlAPIProcess() function where GraphQL mutation input fields are passed directly to shell_exec() without sanitization or escaping. An authenticated user with a valid bearer token can send a GraphQL moduleOperations mutation with backtick-wrapped commands in the module field to execute arbitrary commands on the underlying host as the web server user.
References
Configurations
History
No history.
Information
Published : 2026-04-21 13:16
Updated : 2026-07-14 21:16
NVD link : CVE-2026-40520
Mitre link : CVE-2026-40520
CVE.ORG link : CVE-2026-40520
JSON object : View
Products Affected
freepbx
- api
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
