CVE-2026-28209 | FreePBX up to 16.0.19/17.0.4 Recordings os command injection (GHSA-f558-mp87-58vj)
A vulnerability was found in FreePBX up to 16.0.19/17.0.4 and classified as critical. This impacts an unknown function of the component Recordings Module. The manipulation results in os command injection.
This vulnerability was named CVE-2026-28209. The attack may be performed from remote. There is no available exploit.
It is suggested to upgrade the affected component.