Skip to content
TrustList
News

FreePBX publishes four security advisories on 29 September 2026: update the Pinsets, Sangoma Connect, SIPSTATION and Contact Manager modules

Editorial

By TrustList Editorial

FreePBX’s 29 September advisories fix three high-severity SQL injection flaws (Pinsets, Sangoma Connect RT API, SIPSTATION) and a contact-manager access flaw, after six high or medium advisories on 17 September. All need a login; update the modules.

About FreePBX publishes four security advisories on 29 September 2026: update the Pinsets, Sangoma Connect, SIPSTATION and Contact Manager modules

FreePBX publishes four security advisories on 29 September 2026: update the Pinsets, Sangoma Connect, SIPSTATION and Contact Manager modules

1 October 2026 — FreePBX, the open-source phone-system platform maintained by Sangoma and widely used by small businesses, call centres and managed VoIP providers, published four security advisories on 29 September 2026. Three are rated high. They follow six advisories published on 17 September. The Canadian Centre for Cyber Security issued an advisory (AV26-973) the same day asking administrators to apply the updates.

Not yet independently verified. No exploitation of these flaws has been reported, and none had a CVE number when read on 1 October 2026. The Canadian Centre’s advisory lists different, earlier module versions from FreePBX’s own advisories; the fixed versions below are FreePBX’s. We will update this when it can be confirmed, and remove this note.

The 29 September advisories

Advisory Severity Module Fixed in
Authenticated privilege escalation in the API module through SQL injection in Pinsets High pinsets 16.0.9 / 17.0.4
Low-privilege UCP user can read the full database through SQL injection High sangomartapi (Sangoma Connect RT API) 16.0.57 / 17.0.29
Authenticated admin SQL injection through the SIPSTATION module High sipstation 17.0.4
Low-privilege UCP user can modify other users' contacts Medium contactmanager 16.0.29 / 17.0.8

All four need an authenticated user. Two of them only need a low-privilege account on the User Control Panel (UCP), the self-service portal end users log in to. That matters for any system where UCP is reachable from the internet or where many staff have accounts.

The 17 September set

The earlier advisories include authenticated remote code execution through the UCP and Asterisk Manager Interface (framework 16.0.50 / 17.0.33), authenticated root command injection and unsafe unserialisation in backup restore (backup 16.0.76 / 17.0.13), second-order command execution through Recordings (16.0.21 / 17.0.6), arbitrary file read through the call-recording report, and an unauthenticated stored cross-site scripting flaw in which a crafted inbound caller ID is stored and runs in CEL Reports (cel 16.0.21 / 17.0.3). That last one needs no login at all: a phone call is enough to plant it.

What to do

  • Update modules now through the module admin or fwconsole ma upgradeall, then check the versions against the table above.
  • Keep UCP and the admin interface off the open internet, or behind a VPN and the FreePBX firewall's trusted-zone rules.
  • Review UCP accounts and remove ones nobody uses; two of this week's flaws start from a low-privilege UCP login.
  • If a provider hosts your PBX, ask which module versions you are on and when they were updated.
  • Watch FreePBX's advisory page: FreePBX flaws have been exploited before (CVE-2025-57819 in 2025), so do not wait for a CVE number before patching.

Sources

Categories & features

  • Cybersecurity
  • Vulnerability Management
  • VOIP
  • VoIP Software
  • Call Center Software
  • Telephony Software