VYPR
High severity7.2NVD Advisory· Published Apr 21, 2026· Updated Jul 14, 2026

CVE-2026-40520

CVE-2026-40520

Description

FreePBX api module version 17.0.8 and prior contain a command injection vulnerability in the initiateGqlAPIProcess() function where GraphQL mutation input fields are passed directly to shell_exec() without sanitization or escaping. An authenticated user with a valid bearer token can send a GraphQL moduleOperations mutation with backtick-wrapped commands in the module field to execute arbitrary commands on the underlying host as the web server user.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Freepbx/API2 versions
    cpe:2.3:a:freepbx:api:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:freepbx:api:*:*:*:*:*:*:*:*range: <17.0.8
    • (no CPE)range: <=17.0.8
  • Range: <=17.0.8

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.