CVE-2026-46376 is an authentication weakness in FreePBX affecting the User Control Panel (UCP). In affected versions, initial generic UCP templates can retain hard-coded sample credentials after setup. If an administrator enables UCP and does not immediately change those initial template credentials, an unauthenticated remote attacker may be able to log in to UCP using those built-in credentials. The issue affects FreePBX from 15.0.42 up to, but not including, 16.0.45 and 17.0.7. The flaw is classified as CWE-798 because access can be obtained through credentials embedded in the product’s initial template workflow rather than attacker-supplied valid account credentials.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone Python proof-of-concept for CVE-2026-46376, a FreePBX User Management/UCP issue caused by hard-coded credentials. The repo contains only two files: a README describing the vulnerability, affected versions, usage, and mitigation; and poc.py, the executable exploit script. The main capability is unauthenticated web access to FreePBX UCP by logging in as the statically created template account FreePBXUCPTemplateCreator with password 1a2b3c@fd48jshs03123ld. The script first performs pre-flight checks: it requests the base target URL to verify reachability, fetches /admin/config.php to extract a FreePBX version string, and requests /ucp/index.php to confirm the UCP interface is present. For exploitation, it fetches /ucp/index.php again to scrape a CSRF token, then submits a POST to /ucp/ajax.php with module=User and command=login, along with the hard-coded credentials and AJAX header. A JSON response with status=true is treated as successful exploitation. The README and visible code also indicate two additional methods beyond the primary credential abuse path: an unlock-key/template bypass using query parameters ?unlockkey=&templateid=, and attempts against common default ACP/admin credentials (admin/admin, admin/password, maint/password, ampuser/amp109). Because the script includes actual authentication attempts and multiple exploitation paths, it is more than a detector, but it remains an operational PoC rather than a weaponized framework module. No reverse shell, command execution, or post-exploitation payload is present. The result of successful exploitation is authenticated application access to the FreePBX User Control Panel and possible identification of weak/default admin credentials. The exploit is network/web-based and depends on the target having the vulnerable UCP template setup previously run and the static password still unchanged.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A vulnerability in FreePBX where hard-coded initial template credentials can allow unauthenticated access to the User Control Panel (UCP) if administrators do not change the default credentials after enabling UCP.
A critical authentication bypass / unauthorized access vulnerability in FreePBX User Control Panel caused by hard-coded credentials in the userman module, allowing unauthenticated access to user portals on affected versions.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.