Summary
CVE-2026-73663 is a critical, unauthenticated SQL injection vulnerability in the missedcall module of FreePBX, the widely used open-source PBX/VoIP management platform. The flaw allows a remote, unauthenticated attacker to inject SQL via a crafted SIP From header, corrupting the FreePBX database and potentially modifying administrator control panel accounts to gain unauthorized system access. The issue carries a CVSS v4.0 base score of 9.3 (Critical).
Technical details
- Root cause: The
missedcallmodule logs the inbound Caller ID (CNAM) name to the database whenever a call to a monitored extension goes unanswered. The INSERT query is built by directly concatenating the caller name string into the SQL statement, with no escaping or use of bound/parameterized queries. - Trigger conditions: The module must be installed and actively monitoring at least one extension. An attacker simply places a call (or causes a call) to a monitored extension that goes unanswered, with a maliciously crafted Caller ID/SIP
Fromheader containing a SQL injection payload. - Why it’s exploitable at scale: Unlike traditional PSTN CNAM fields, which are limited to 15 characters, inbound Caller ID Name values delivered over SIP trunks or direct internet-facing SIP calling are not length-restricted, giving attackers ample room to inject arbitrary SQL payloads.
- Attack vector: Network-based, no authentication or user interaction required (AV:N/PR:N/UI:N).
- Impact: Successful exploitation can corrupt the FreePBX database and modify FreePBX administrator control panel accounts/credentials, allowing the attacker to obtain unauthorized administrative access to the PBX system — a potential foothold for further compromise of telephony infrastructure.
- Root cause type: CWE-89 (Improper Neutralization of Special Elements used in an SQL Command / SQL Injection).
- The bug has reportedly existed since the
missedcallmodule was created in 2023.
Affected software
- FreePBX 16 — all versions prior to 16.0.11
- FreePBX 17 — all versions prior to 17.0.6
- Only systems with the
missedcallmodule installed and configured to monitor extensions are exposed.
Severity
- CVSS v4.0 Base Score: 9.3 (Critical)
- Vector:
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Mitigation and recommended actions
- Immediate: Update the
missedcallmodule / FreePBX to the patched releases — FreePBX 16.0.11 or FreePBX 17.0.6 (or later). - If immediate patching is not possible:
- Restrict inbound calls so that only known, trusted SIP trunks can reach monitored extensions.
- Enforce strong access controls on the FreePBX admin interface (User Management, VPN, MFA, or SAML) to limit the blast radius if an account is manipulated.
- Use the FreePBX Firewall module to block untrusted/hostile network sources from reaching SIP signaling.
- Configure Session Border Controllers (SBCs) to filter and sanitize SIP
Fromheaders before they reach the PBX. - If the
missedcallmodule is not required, disable or uninstall it to eliminate exposure entirely.

