CVE-2026-28287 | FreePBX up to 16.0.19/17.0.4 Recordings os command injection (GHSA-9vv6-h8v6-rp4q)
A vulnerability was found in FreePBX up to 16.0.19/17.0.4. It has been rated as critical. Affected by this issue is some unknown functionality of the component Recordings Module. Performing a manipulation results in os command injection.
This vulnerability is identified as CVE-2026-28287. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is advised.