CVE-2026-72578 HIGH

CVE-2026-72578: FreePBX Framework - Missing CSRF Protection in Admin Panel Ajax Dispatcher

Vendor Freepbx
Product FreePBX Framework
Weakness CWE-352 · CSRF
Published August 10, 2026
Last update August 10, 2026

CVSS base score

8.8/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

A cross-site request forgery (CSRF) vulnerability in FreePBX Framework 17.0 allows an unauthenticated remote attacker to perform administrative actions on behalf of an authenticated administrator.

Key dates

02Disclosure timeline

August 10, 2026 CVE published
August 10, 2026 Record updated

Related vulnerabilities

04Related CVE