CVE-2026-44239Sangoma · Freepbx
Vulnerability data via NVD (ingested)
FreePBX is an open source IP PBX. Prior to 16.0.22 and 17.0.5, the Dashboard module's getcontent AJAX handler includes PHP files based on user-supplied input without path sanitization. The $_REQUEST['rawname'] parameter is concatenated into an include() call with a .class.php suffix, allowing path traversal via ../ sequences to include arbitrary .class.php files from the filesystem. The included file's PHP code executes before the subsequent class instantiation error occurs. This vulnerability is fixed in 16.0.22 and 17.0.5.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-44239product:"Sangoma Freepbx"http.html:"Freepbx"More intel sources (5)
vuln:CVE-2026-44239vulnerabilities.cve_id: CVE-2026-44239CVE-2026-44239CVE-2026-44239"CVE-2026-44239" exploit -site:nvd.nist.gov