CVE-2026-40520
EUVD-2026-2408621.04.2026, 13:16
FreePBX api module version 17.0.8 and prior contain a command injection vulnerability in the initiateGqlAPIProcess() function where GraphQL mutation input fields are passed directly to shell_exec() without sanitization or escaping. An authenticated user with a valid bearer token can send a GraphQL moduleOperations mutation with backtick-wrapped commands in the module field to execute arbitrary commands on the underlying host as the web server user.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| freepbx | api | 𝑥 < 17.0.8 |
𝑥
= Vulnerable software versions
References