External risk intelligence

FreePBX UCP Hardcoded Credentials Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-46376

FreePBX is an IP PBX system, a product role designed to be accessible as a communication gateway. The User Control Panel (UCP) is frequently exposed to the internet to allow remote users to access telephony features. Because this vulnerability allows unauthenticated access to a web-based management interface, it targets an inherently public-facing service.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a critical vulnerability in FreePBX, an open-source IP PBX system. Unauthenticated users may gain access to the User Control Panel (UCP) if default credentials were not changed during initial setup. This could potentially expose communication functionalities to unauthorized access.

  • Unauthenticated access to FreePBX User Control Panel.
  • Critical vulnerability impacts internet-facing communication systems.
  • Confirm if this system is deployed and unpatched.

Attack Path

How an attacker could exploit the issue

An attacker could gain unauthorized access to the FreePBX User Control Panel by exploiting hard-coded initial credentials. This is possible if the administrator did not change these default credentials after enabling the User Control Panel. While authenticated access is needed for the initial setup, the vulnerability allows unauthenticated users to bypass security measures and access the panel without further administrative intervention.

  • Unauthenticated network access to the UCP.
  • Exploits initial template credentials.
  • Grants access to sensitive user control functions.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, unauthenticated users could access the FreePBX User Control Panel (UCP) if initial template credentials were not changed. This could expose system and user data.

  • System and user data
  • Unauthenticated access to UCP
  • Unauthorized access to telephony features

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability in FreePBX impacts the User Control Panel (UCP) and requires immediate attention from infrastructure and platform teams responsible for its deployment. The first actionable step is to identify all instances of FreePBX, confirm UCP accessibility and business criticality, and then assign ownership for remediation.

  • Infrastructure and platform teams own this.
  • Verify UCP access and business criticality.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is FreePBX and how is it used?

FreePBX is an open-source IP PBX system used to manage and route telephony traffic. It acts as a communication gateway, allowing organizations to handle voice calls over data networks. It includes features like the User Control Panel (UCP), which lets individual users manage their telephony settings, extensions, and personal communication preferences directly through a web-based interface.

What does CWE-798 mean for CVE-2026-46376?

CWE-798 refers to the use of hard-coded credentials. In the context of this CVE, it means the software contains default, built-in login information for its User Control Panel templates. If these templates are enabled but the administrator fails to change the initial credentials immediately, an attacker can use those known defaults to bypass the authentication process and gain unauthorized access to the panel.

Does this vulnerability trigger if I use unique login credentials?

No. The vulnerability specifically relies on the presence of the hard-coded initial template credentials. If an administrator has already updated or changed these credentials during the setup process, the mechanism that permits unauthenticated access is effectively neutralized. The risk exists primarily when the system is left in its default, out-of-the-box configuration after the User Control Panel has been enabled.

Is my system at higher risk if it faces the internet?

Yes. According to Halo Surface Signal, FreePBX is designed as a communication gateway and its User Control Panel is frequently exposed to the internet to support remote users. Because this vulnerability allows unauthenticated access, internet-facing instances are significantly more accessible to unauthorized users compared to systems restricted to an internal, private network.

How should I respond to this vulnerability?

First, identify all deployed instances of FreePBX within your infrastructure. Once identified, verify whether the User Control Panel is enabled and check if the default template credentials have been changed. If you are running an affected version, coordinate with your team to update the software to the patched version—16.0.45 or 17.0.7—which addresses this security gap.

References