What is CVE-2026-73660?
In FreePBX prior to versions 16.0.6 and 17.0.5.4, the Text-To-Speech module allows an authenticated administrator to save a TTS destination name that is HTML-encoded for storage, decoded during dialplan generation, passed as an AGI argument, and used to build filenames, leading to a security vulnerability. This issue affects FreePBX IP PBX systems and can be exploited with admin privileges. Upgrading to the fixed versions is recommended.
Azərbaycanca: FreePBX-in Text-To-Speech (TTS) modulunda autentifikasiya olunmuş administratorun saxladığı TTS təyinat adı dialplan generasiyası zamanı deşifrə edilərək AGI arqumenti kimi istifadə olunur və fayl adlarının qurulmasında təhlükəsizlik zəifliyinə səbəb olur. 16.0.6 və 17.0.5.4 versiyalarından əvvəlki sistemlər təsirlənir, administrator hüquqları ilə istismar mümkündür. Ən son versiyalara yenilənmə tövsiyə edilir.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which FreePBX versions are affected by CVE-2026-73660?
This vulnerability affects FreePBX systems prior to version 16.0.6 and 17.0.5.4.
What level of access is required to exploit CVE-2026-73660?
Exploitation of this vulnerability requires authenticated administrator privileges.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.