LOWVulnerability

CVE-2026-73661

FreePBX is an open source IP PBX. Prior to 16.0.47 and 17.0.30, the FreePBX Framework module permits a crafted backup to restore the hidden AUTHTYPE setting with the value none through runRestore() in amp_conf/htdocs/admin/libraries/Builtin/Restore.php. An authenticated user with sufficient backup-restore access or write access to backup files can thereby disable FreePBX authentication during restoration, bypassing the user-interface removal of AUTHTYPE=none. This issue is fixed in versions 16.0.47 and 17.0.30.

Properties

cve_id
CVE-2026-73661
signal_observed_at
2026-09-18T21:50:18+00:00
published_at
2026-08-13T22:17:27.627
last_modified
2026-09-18T20:05:53.723

Related Entities (2)

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (1)

[Weakness]External Control of System or Configuration Setting

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-73661 — Ninja Signal Threat Intelligence | Ninja Signal