# CVE-2026-73661

## Summary

- **CVE ID:** CVE-2026-73661
- **Severity:** HIGH
- **CVSS Score:** 8.6 (CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N)
- **CWE:** CWE-15
- **Published:** Aug 13, 2026
- **Last Modified:** Aug 14, 2026

## Description

FreePBX is an open source IP PBX. Prior to 16.0.47 and 17.0.30, the FreePBX Framework module permits a crafted backup to restore the hidden AUTHTYPE setting with the value none through runRestore() in amp_conf/htdocs/admin/libraries/Builtin/Restore.php. An authenticated user with sufficient backup-restore access or write access to backup files can thereby disable FreePBX authentication during restoration, bypassing the user-interface removal of AUTHTYPE=none. This issue is fixed in versions 16.0.47 and 17.0.30.

## Affected Products

- FreePBX — framework (< 16.0.47)
- FreePBX — framework (>= 17.0.1, < 17.0.30)

## References

- [CNA](https://github.com/FreePBX/security-reporting/security/advisories/GHSA-f6hc-rqxg-ch86)
- [CNA](https://github.com/FreePBX/framework/commit/0591581654bc269df05cbb7093645d6934d4d861)
- [CNA](https://github.com/FreePBX/framework/commit/ea684be89abb393d1aff7f979d5fd751ff338dfd)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.34%
- **EPSS Percentile:** 26.5

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._