Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 01 Jun 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sangoma
Sangoma freepbx |
|
| CPEs | cpe:2.3:a:sangoma:freepbx:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Sangoma
Sangoma freepbx |
|
| Metrics |
cvssV3_1
|
Fri, 29 May 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Freepbx
Freepbx security-reporting |
|
| Vendors & Products |
Freepbx
Freepbx security-reporting |
Fri, 29 May 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 29 May 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FreePBX is an open source IP PBX. Prior to 17.0.8, the FreePBX api module's OAuth2 implementation does not sufficiently validate client credentials during token issuance. Knowledge of a valid client_id is required. The validateClient() method in ClientRepository.php unconditionally returns true, allowing any party with knowledge of a valid client_id to obtain OAuth2 access tokens without providing the correct client_secret. This vulnerability is fixed in 17.0.8. | |
| Title | FreePBX: Authenticated Access can lead to Subsequent OAuth2 Authentication Bypass in API Module | |
| Weaknesses | CWE-1390 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-30T03:57:39.482Z
Reserved: 2026-05-05T15:42:40.519Z
Link: CVE-2026-44237
Updated: 2026-05-29T14:03:19.159Z
Status : Analyzed
Published: 2026-05-29T14:16:27.060
Modified: 2026-06-01T18:42:00.963
Link: CVE-2026-44237
No data.
OpenCVE Enrichment
Updated: 2026-05-29T15:45:16Z