CVE-2026-44238 HIGH

CVE-2026-44238: FreePBX: Authenticated SQL Injection via ORDER BY in CDR Reports

Vendor Freepbx
Product security-reporting
Weakness CWE-89 · SQLi
Published May 29, 2026
Last update May 30, 2026

CVSS base score

8.5/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

FreePBX is an open source IP PBX. Prior to 16.0.50 and 17.0.11, the CDR Reports module page allows SQL injection through the order and sort POST parameters. Authentication with a FreePBX Administration Control Panel account that has CDR section access is required. Full administrator privileges are not needed. This vulnerability is fixed in 16.0.50 and 17.0.11.

Key dates

02Disclosure timeline

May 29, 2026 CVE published
May 30, 2026 Record updated