What is CVE-2026-73661?
A vulnerability in FreePBX Framework module (CVE-2026-73661) allows an authenticated user with sufficient privileges to restore the AUTHTYPE setting to `none` via a crafted backup, potentially disabling authentication. Versions prior to 16.0.47 and 17.0.30 are affected; upgrading to the fixed versions is recommended.
Azərbaycanca: FreePBX-in Framework modulunda aşkar edilmiş boşluq (CVE-2026-73661) səlahiyyətli istifadəçiyə xüsusi hazırlanmış backup vasitəsilə AUTHTYPE parametrini `none` olaraq bərpa etməyə imkan verir. Bu, autentifikasiyanı sıradan çıxara bilər. 16.0.47 və 17.0.30 versiyalarından əvvəlki versiyalar təsirlənir, yeniləmə tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
How can the CVE-2026-73661 vulnerability disable authentication in FreePBX?
An authenticated user with sufficient privileges can restore the AUTHTYPE setting to `none` via a crafted backup, potentially disabling authentication.
Which FreePBX versions should I upgrade to in order to protect against CVE-2026-73661?
You should upgrade the FreePBX Framework module to version 16.0.47, 17.0.30, or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.