Vulnerability Description
FreePBX is an open source IP PBX. From versions 16.0.17.2 to before 16.0.20 and from version 17.0.2.4 to before 17.0.5, a command injection vulnerability exists in FreePBX when using the ElevenLabs Text-to-Speech (TTS) engine in the recordings module. This issue has been patched in versions 16.0.20 and 17.0.5.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sangoma | Freepbx | >= 16.0.17.2, < 16.0.20 |
Related Weaknesses (CWE)
References
- https://github.com/FreePBX/security-reporting/security/advisories/GHSA-f558-mp87MitigationVendor Advisory
FAQ
What is CVE-2026-28209?
CVE-2026-28209 is a vulnerability with a CVSS score of 7.2 (HIGH). FreePBX is an open source IP PBX. From versions 16.0.17.2 to before 16.0.20 and from version 17.0.2.4 to before 17.0.5, a command injection vulnerability exists in FreePBX when using the ElevenLabs Te...
How severe is CVE-2026-28209?
CVE-2026-28209 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-28209?
Check the references section above for vendor advisories and patch information. Affected products include: Sangoma Freepbx.