CVE-2026-40520
Published Apr 21, 2026FreePBX api module version 17.0.8 and prior contain a command injection vulnerability in the initiateGqlAPIProcess() function where GraphQL mutation input fields are passed direct…
- evidence mentions
- 4
- Buzz score
- 22.6