Vulnerability Intelligence Report
FreePBX: Unauthenticated SQL injection in FreePBX missedcall via inbound Caller ID name leads to administrator takeover
CVE-2026-73663
FreePBX is an open source IP PBX. From 16.0.0 until 16.0.11 and 17.0.4, the FreePBX missedcall module places the inbound Caller ID name from crafted SIP From headers into the missedcalllog INSERT in agi-bin/missedcallnotify.php without escaping or bound parameters. An unauthenticated caller can inject SQL when a monitored extension goes unanswered, corrupting the database and modifying FreePBX administrator accounts to obtain unauthorized remote access. This issue is fixed in versions 16.0.11 and 17.0.4.
Injection
No Active Exploit Signals
CVSS Base Score
9.3
CRITICAL
EPSS Probability:0.95%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-89 ↗CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| FreePBX | missedcall | < 16.0.11 (affected), >= 17.0.1, < 17.0.4 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.954%
Vulnerability Class
Injection
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | GitHub, Inc. · Vendor · USA |
| Reserved | 2026-08-13T14:04:09 |
| Published | 2026-08-13T21:29:14 |
| Last Updated | 2026-08-14T16:27:05 |
Community Chatter & Buzz