VYPR
High severity8.8NVD Advisory· Published May 29, 2026· Updated Jul 21, 2026

CVE-2026-44239

CVE-2026-44239

Description

FreePBX is an open source IP PBX. Prior to 16.0.22 and 17.0.5, the Dashboard module's getcontent AJAX handler includes PHP files based on user-supplied input without path sanitization. The $_REQUEST['rawname'] parameter is concatenated into an include() call with a .class.php suffix, allowing path traversal via ../ sequences to include arbitrary .class.php files from the filesystem. The included file's PHP code executes before the subsequent class instantiation error occurs. This vulnerability is fixed in 16.0.22 and 17.0.5.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Range: <16.0.22,<17.0.5
  • Freepbx/Freepbxllm-fuzzy2 versions
    <16.0.22, <17.0.5+ 1 more
    • (no CPE)range: <16.0.22, <17.0.5
    • cpe:2.3:a:sangoma:freepbx:*:*:*:*:*:*:*:*range: <16.0.22

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.