CVE-2026-72578
Severity CVSS v4.0:
Pending analysis
Type:
CWE-352
Cross-Site Request Forgery (CSRF)
Publication date:
10/08/2026
Last modified:
10/08/2026
Description
A cross-site request forgery (CSRF) vulnerability in FreePBX Framework 17.0 allows an unauthenticated remote attacker to perform administrative actions on behalf of an authenticated administrator.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH


