CVE-2026-54674 - Authenticated Command Injection in FreePBX UCP Interface
CVE ID :CVE-2026-54674 Published : Sept. 28, 2026, 6:17 p.m. | 1 hour, 58 minutes ago Description :FreePBX is an open source IP PBX. Prior to versions 16.0.39 and 17.0.7, users authenticated via User Control Panel (UCP) are able to execute arbitrary commands on the PBX as the webserver user...