What is CVE-2026-72578?
This is a Cross-Site Request Forgery (CSRF) vulnerability found in FreePBX Framework 17.0. An unauthenticated remote attacker can perform administrative actions on behalf of an authenticated administrator. To mitigate this, it is recommended to update FreePBX Framework or apply the security patch provided by the vendor.
Azərbaycanca: Bu, FreePBX Framework 17.0-da aşkarlanmış CSRF (Cross-Site Request Forgery) zəifliyidir. Autentifikasiya olunmamış uzaqdan hücumçu, autentifikasiya olunmuş administrator adından administrativ əməliyyatlar icra edə bilər. Təsirə məruz qalan sistemlərdə FreePBX Framework-in yenilənməsi və ya təchizatçı tərəfindən verilən təhlükəsizlik yamasının tətbiqi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-352
FAQ2
What can an attacker achieve by exploiting CVE-2026-72578?
An unauthenticated remote attacker can perform administrative actions on behalf of an authenticated administrator.
How to mitigate the CVE-2026-72578 vulnerability?
It is recommended to update FreePBX Framework or apply the security patch provided by the vendor.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.