CVE Explorer
CVE-2026-26978
FreePBX is an open source IP PBX. In versions below 16.0.71 and 17.0.6, the backup module does not properly sanitize data during restore operations, potentially leading to compromise if the backup contains carefully crafted hostile data. During backup restore operations, FreePBX extracts selected files from a user-supplied tar archive. If a malicious file exists in the archive, it is read and passed directly to unserialize() without validation, class restrictions, or integrity checks. This issue
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"security-reporting","vendor":"FreePBX","versions":[{"status":"affected","version":"< 16.0.71"},{"status":"affected","version":">= 17.0.0, < 17.0.6"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:5637e6b54b63f763ff1e8e60c20949e3adca8a5ac1ae2bc5884a93c40103436f · sha256:81c93ae4db07bb7b… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":8.6,"baseSeverity":"HIGH","privilegesRequired":"LOW","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:5637e6b54b63f763ff1e8e60c20949e3adca8a5ac1ae2bc5884a93c40103436f · sha256:81c93ae4db07bb7b… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-502","description":"CWE-502: Deserialization of Untrusted Data","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:5637e6b54b63f763ff1e8e60c20949e3adca8a5ac1ae2bc5884a93c40103436f · sha256:81c93ae4db07bb7b… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"name":"https://github.com/FreePBX/backup/commit/45c57e1207cbf9fd1c5f76f8a3e72d204a69a472","tags":["x_refsource_MISC"],"url":"https://github.com/FreePBX/backup/commit/45c57e1207cbf9fd1c5f76f8a3e72d204a69a472"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:5637e6b54b63f763ff1e8e60c20949e3adca8a5ac1ae2bc5884a93c40103436f · sha256:81c93ae4db07bb7b… · /containers/cna/references/1
{"name":"https://github.com/FreePBX/backup/commit/64781af5c80cce0cff21a981be4d8e6a7a71f2c4","tags":["x_refsource_MISC"],"url":"https://github.com/FreePBX/backup/commit/64781af5c80cce0cff21a981be4d8e6a7a71f2c4"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:5637e6b54b63f763ff1e8e60c20949e3adca8a5ac1ae2bc5884a93c40103436f · sha256:81c93ae4db07bb7b… · /containers/cna/references/2
{"name":"https://github.com/FreePBX/security-reporting/security/advisories/GHSA-5v7h-49gr-jcwr","tags":["x_refsource_CONFIRM"],"url":"https://github.com/FreePBX/security-reporting/security/advisories/GHSA-5v7h-49gr-jcwr"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:5637e6b54b63f763ff1e8e60c20949e3adca8a5ac1ae2bc5884a93c40103436f · sha256:81c93ae4db07bb7b… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.