PT-2026-44842 · Freepbx · Freepbx

·

CVE-2026-44237

·

Published

2026-05-29

·

Updated

2026-07-21

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions FreePBX versions prior to 17.0.8
Description The OAuth2 implementation in the api module fails to properly validate client credentials during token issuance. Specifically, the validateClient() function in ClientRepository.php unconditionally returns true. This allows an attacker who knows a valid client id to obtain OAuth2 access tokens without providing the required client secret.
Recommendations Update to version 17.0.8.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44237
GHSA-VGJF-4H63-8VCC

Affected Products

Freepbx