<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>FreePBX (&gt;= 15.0.42, &lt; 16.0.45, &gt;= 17.0.1, &lt; 17.0.7) — CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/freepbx--15.0.42--16.0.45--17.0.1--17.0.7/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 02 Jun 2026 08:35:31 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/freepbx--15.0.42--16.0.45--17.0.1--17.0.7/feed.xml" rel="self" type="application/rss+xml"/><item><title>FreePBX Hardcoded Credentials Vulnerability (CVE-2026-46376)</title><link>https://feed.craftedsignal.io/briefs/2026-06-freepbx-hardcoded-credentials/</link><pubDate>Tue, 02 Jun 2026 08:35:31 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-06-freepbx-hardcoded-credentials/</guid><description>A critical vulnerability, CVE-2026-46376, exists in FreePBX due to the use of hard-coded credentials in the User Control Panel (UCP) generic template setup process, allowing an unauthenticated, remote attacker to gain unauthorized access to user accounts and manipulate user settings if default template credentials are not immediately changed by the administrator after enabling UCP.</description><content:encoded><![CDATA[<p>A critical vulnerability, CVE-2026-46376, exists in FreePBX versions 15.0.42 to 16.0.45 and 17.0.1 to 17.0.7. This vulnerability stems from the use of hard-coded credentials within the User Control Panel (UCP) generic template setup. The UCP generic template setup process is optional and designed to simplify common UCP deployments. However, if administrators do not immediately change these default credentials, unauthenticated attackers can gain access to the UCP. Successful exploitation grants attackers unauthorized access to user accounts, exposure of sensitive user data, and manipulation of user settings and configurations. The FreePBX project released an advisory for this vulnerability, urging users to apply patches and mitigations immediately to prevent potential exploitation.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>An attacker identifies a FreePBX instance with the UCP enabled and the default UCP generic template setup used.</li>
<li>The attacker attempts to access the UCP login page, which is typically exposed over the network.</li>
<li>The attacker uses the hard-coded default credentials to authenticate to the UCP.</li>
<li>Upon successful authentication, the attacker gains access to user accounts.</li>
<li>The attacker then leverages the unauthorized access to view sensitive user data, such as call logs, voicemails, and contact lists.</li>
<li>The attacker manipulates user settings and configurations within the UCP.</li>
<li>Depending on the scope of the account&rsquo;s permissions, the attacker could modify call routing rules, forwarding numbers, or even disable accounts.</li>
<li>The attacker gains control over the VoIP server&rsquo;s functionality, potentially leading to call interception, eavesdropping, or denial of service.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2026-46376 can lead to unauthorized access to user accounts, exposing sensitive user data like call logs and voicemails. Attackers can manipulate user settings and configurations, potentially disrupting VoIP services and gaining control over the communication infrastructure. Given the widespread use of FreePBX in various sectors, including small businesses and large enterprises, the impact could range from data breaches and financial losses to significant disruptions in communication services. The vulnerability has a CVSS score of 9.3, highlighting the severity of the risk.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Immediately update the userman module to the latest version, which randomizes the password, as recommended by FreePBX.</li>
<li>Ensure only authorized users have access to the FreePBX Administrator Control Panel (ACP) by using FreePBX User Management, SysAdmin VPN, MFA, or SAML modules, as mentioned in the advisory.</li>
<li>Implement access control measures, such as using the FreePBX Firewall module, to deny access from hostile networks to the ACP and the UCP, as stated in the FreePBX advisory.</li>
<li>Monitor and detect suspicious activity related to unauthorized access attempts on the UCP. Organizations should enhance their monitoring capabilities as recommended by the CCB.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category><category>cve</category><category>voip</category><category>freepbx</category><category>credential-access</category></item></channel></rss>