ALERT AI helped find CopyFail exploit to give a user root access to in all Linux distros

Screenshot 2026-05-05 at 1.45.48 PM.png
When our first server gets compromised, I'll let you know. AND... you do the same.
 
Last edited:
UPDATED.

To exploit this FreePBX remote code execution bug, you'd have to

1. find a FreePBX system (or IncrediblePBX system, I use these names interchangeably as they are both affected) that was NOT patched with the November 2025, update to the filestore module 17.0.3.
2. And the Debian 12 OS be not patched for the Copy.Fail root priviliege escalation exploit.
3. And you'd need a simple login account into the Freepbx web interface, and it doesn't have to be an admin login, it can be a regular user login.

Steps to exploit: you'll start as user asterisk, remotely run the one line python copy fail exploit command, and you're root, then you can install a persistent web shell, or run any command.

Note: an updated Incredible / FreePBX is not susceptible to this attack, as the filestore module version is....
Code:
$ sudo fwconsole ma list | grep filestore
| filestore         | 17.0.3     | Enabled                           | AGPLv3     |
 
Last edited:
 

Members online

No members online now.

Forum statistics

Threads
26,688
Messages
174,412
Members
20,257
Latest member
Dempan
Get 3CX - Absolutely Free!

Link up your team and customers Phone System Live Chat Video Conferencing

Hosted or Self-managed. Up to 10 users free forever. No credit card. Try risk free.

3CX
A 3CX Account with that email already exists. You will be redirected to the Customer Portal to sign in or reset your password if you've forgotten it.
Back
Top