CVE-2026-54675: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in FreePBX security-reporting
FreePBX security-reporting prior to versions 16.0.10 and 17.0.5 contains a critical path traversal vulnerability in its sound language upload and conversion functionality. This flaw allows an authenticated attacker with a known username to perform arbitrary file writes, potentially leading to remote code execution. The vulnerability arises from insufficient path sanitization during file conversion, enabling placement of malicious PHP files in the web server's root directory. The issue has been patched in versions 16.0.10 and 17.0.5.
AI Analysis
Technical Summary
CVE-2026-54675 is a critical path traversal vulnerability (CWE-22) in FreePBX security-reporting's sound language upload and conversion feature. Authenticated attackers with a known username can exploit insufficient path sanitization to write arbitrary files, including malicious PHP scripts, to the web server root directory. This arbitrary file write can lead directly to remote code execution. The vulnerability affects versions prior to 16.0.10 and 17.0.5 and has been addressed in these versions.
Potential Impact
An authenticated attacker can exploit this vulnerability to write arbitrary files to the web server root directory, enabling remote code execution. This compromises the confidentiality, integrity, and availability of the affected system. The vulnerability requires authentication with a known username but no user interaction and has a high severity score of 8.7.
Mitigation Recommendations
Upgrade FreePBX security-reporting to version 16.0.10 or later, or 17.0.5 or later, where this vulnerability has been patched. Applying these official fixes fully mitigates the risk of arbitrary file writes and remote code execution via this path traversal flaw.
CVE-2026-54675: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in FreePBX security-reporting
Description
FreePBX security-reporting prior to versions 16.0.10 and 17.0.5 contains a critical path traversal vulnerability in its sound language upload and conversion functionality. This flaw allows an authenticated attacker with a known username to perform arbitrary file writes, potentially leading to remote code execution. The vulnerability arises from insufficient path sanitization during file conversion, enabling placement of malicious PHP files in the web server's root directory. The issue has been patched in versions 16.0.10 and 17.0.5.
CVSS v4.0
Score 8.7high
Affected software
FreePBX
security-reporting
pkg:github/freepbx/security-reportingRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-54675 is a critical path traversal vulnerability (CWE-22) in FreePBX security-reporting's sound language upload and conversion feature. Authenticated attackers with a known username can exploit insufficient path sanitization to write arbitrary files, including malicious PHP scripts, to the web server root directory. This arbitrary file write can lead directly to remote code execution. The vulnerability affects versions prior to 16.0.10 and 17.0.5 and has been addressed in these versions.
Potential Impact
An authenticated attacker can exploit this vulnerability to write arbitrary files to the web server root directory, enabling remote code execution. This compromises the confidentiality, integrity, and availability of the affected system. The vulnerability requires authentication with a known username but no user interaction and has a high severity score of 8.7.
Mitigation Recommendations
Upgrade FreePBX security-reporting to version 16.0.10 or later, or 17.0.5 or later, where this vulnerability has been patched. Applying these official fixes fully mitigates the risk of arbitrary file writes and remote code execution via this path traversal flaw.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-06-15T22:53:58.561Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6abb1b0bf7a7c541069f197c
Added to database: 09/29/2026, 01:57:31 UTC
Last enriched: 09/29/2026, 01:58:32 UTC
Last updated: 09/29/2026, 03:32:31 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.