CVE-2026-73662 | FreePBX up to 17.0.6 Music on Hold Music.class.php validateCustomConfiguration os command injection
A vulnerability classified as problematic has been found in FreePBX up to 17.0.6. This issue affects the function validateCustomConfiguration of the file Music.class.php of the component Music on Hold. This manipulation causes os command injection.
The identification of this vulnerability is CVE-2026-73662. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.VulDB Recent EntriesRead More