CVE-2026-73664 | FreePBX up to 17.0.10 publicKeySave AJAX endpoint Backup.class.php improper authorization
A vulnerability categorized as very critical has been discovered in FreePBX up to 17.0.10. This affects an unknown part of the file Backup.class.php of the component publicKeySave AJAX endpoint. Executing a manipulation can lead to improper authorization.
This vulnerability appears as CVE-2026-73664. The attack may be performed from remote. There is no available exploit.
It is advisable to upgrade the affected component.VulDB Recent EntriesRead More