FreePBX publishes four security advisories on 29 September 2026: update the Pinsets, Sangoma Connect, SIPSTATION and Contact Manager modules
EditorialBy TrustList Editorial
FreePBX’s 29 September advisories fix three high-severity SQL injection flaws (Pinsets, Sangoma Connect RT API, SIPSTATION) and a contact-manager access flaw, after six high or medium advisories on 17 September. All need a login; update the modules.
- Cybersecurity
- Vulnerability Management
- VOIP
- VoIP Software
- +2 more
About FreePBX publishes four security advisories on 29 September 2026: update the Pinsets, Sangoma Connect, SIPSTATION and Contact Manager modules
FreePBX publishes four security advisories on 29 September 2026: update the Pinsets, Sangoma Connect, SIPSTATION and Contact Manager modules
1 October 2026 — FreePBX, the open-source phone-system platform maintained by Sangoma and widely used by small businesses, call centres and managed VoIP providers, published four security advisories on 29 September 2026. Three are rated high. They follow six advisories published on 17 September. The Canadian Centre for Cyber Security issued an advisory (AV26-973) the same day asking administrators to apply the updates.
Not yet independently verified. No exploitation of these flaws has been reported, and none had a CVE number when read on 1 October 2026. The Canadian Centre’s advisory lists different, earlier module versions from FreePBX’s own advisories; the fixed versions below are FreePBX’s. We will update this when it can be confirmed, and remove this note.
The 29 September advisories
| Advisory | Severity | Module | Fixed in |
|---|---|---|---|
| Authenticated privilege escalation in the API module through SQL injection in Pinsets | High | pinsets | 16.0.9 / 17.0.4 |
| Low-privilege UCP user can read the full database through SQL injection | High | sangomartapi (Sangoma Connect RT API) | 16.0.57 / 17.0.29 |
| Authenticated admin SQL injection through the SIPSTATION module | High | sipstation | 17.0.4 |
| Low-privilege UCP user can modify other users' contacts | Medium | contactmanager | 16.0.29 / 17.0.8 |
All four need an authenticated user. Two of them only need a low-privilege account on the User Control Panel (UCP), the self-service portal end users log in to. That matters for any system where UCP is reachable from the internet or where many staff have accounts.
The 17 September set
The earlier advisories include authenticated remote code execution through the UCP and Asterisk Manager Interface (framework 16.0.50 / 17.0.33), authenticated root command injection and unsafe unserialisation in backup restore (backup 16.0.76 / 17.0.13), second-order command execution through Recordings (16.0.21 / 17.0.6), arbitrary file read through the call-recording report, and an unauthenticated stored cross-site scripting flaw in which a crafted inbound caller ID is stored and runs in CEL Reports (cel 16.0.21 / 17.0.3). That last one needs no login at all: a phone call is enough to plant it.
What to do
- Update modules now through the module admin or
fwconsole ma upgradeall, then check the versions against the table above. - Keep UCP and the admin interface off the open internet, or behind a VPN and the FreePBX firewall's trusted-zone rules.
- Review UCP accounts and remove ones nobody uses; two of this week's flaws start from a low-privilege UCP login.
- If a provider hosts your PBX, ask which module versions you are on and when they were updated.
- Watch FreePBX's advisory page: FreePBX flaws have been exploited before (CVE-2025-57819 in 2025), so do not wait for a CVE number before patching.
Sources
Categories & features
- Cybersecurity
- Vulnerability Management
- VOIP
- VoIP Software
- Call Center Software
- Telephony Software
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- More CybersecurityThe ranking for this subject
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.