Vulnerability record · CVE-2019-19006 · published 21 November 2019
CVE-2019-19006: Sangoma FreePBX improper authentication allows remote admin bypass
Sangoma · Freepbx
FreePBX versions 115.0.16.26, 14.0.13.11, 13.0.197.13 and below contain an incorrect access control flaw (CWE-287 improper authentication) that lets an unauthenticated remote party bypass admin authentication. Because FreePBX is the web management layer for Asterisk-based phone systems, a bypass of this control exposes the full administrative interface.
Description
Sangoma FreePBX 115.0.16.26 and below, 14.0.13.11 and below, 13.0.197.13 and below have Incorrect Access Control.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or interaction required, active CISA KEV listing and high EPSS score make this an urgent patch-first issue.
What it is
FreePBX versions 115.0.16.26, 14.0.13.11, 13.0.197.13 and below contain an incorrect access control flaw (CWE-287 improper authentication) that lets an unauthenticated remote party bypass admin authentication. Because FreePBX is the web management layer for Asterisk-based phone systems, a bypass of this control exposes the full administrative interface.
Impact
An attacker gains full administrative access to the FreePBX management interface without credentials, with high impact to confidentiality, integrity and availability per the CVSS vector. From there they can reconfigure the PBX, including extensions, trunks and call routing, and potentially pivot into the underlying telephony infrastructure.
Attack surface
Reachable over the network via the FreePBX web interface; the CVSS vector is AV:N/AC:L/PR:N/UI:N, so no authentication and no user interaction are required. The record does not specify the exact endpoint or request used for the bypass.
Exploitation
CVE-2019-19006 is listed in CISA KEV with a due date of 2026-02-24, and EPSS gives a 30-day probability of 0.36615 (98.4th percentile), indicating observed exploitation activity. A third-party research reference is tagged Exploit, and no ransomware campaign use is documented.
What to do
- Upgrade FreePBX to a release above the affected 115.0.16.26, 14.0.13.11 and 13.0.197.13 branches per the vendor advisory SEC-2019-001.
- If immediate patching is not possible, restrict management interface access to trusted networks or VPN and follow CISA BOD 22-01 guidance, including discontinuing use if no mitigation is available.
- Place the FreePBX admin interface behind a reverse proxy or firewall rule that blocks untrusted internet access.
- Audit FreePBX admin accounts and configuration for unauthorized changes, and rotate credentials and API keys after remediation.
- Monitor vendor advisories for follow-up fixes, since the record does not enumerate every affected build.
Detection
- Review FreePBX/Asterisk web server logs for admin interface requests that succeed without a preceding authenticated session or login.
- Alert on configuration changes to extensions, trunks, outbound routes or admin users made outside change windows.
- Monitor for unexpected outbound calling or toll fraud patterns from the PBX that could follow an admin compromise.
- Correlate network access to the FreePBX management port from untrusted source addresses with subsequent admin activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2019-19006 to the Known Exploited Vulnerabilities catalog on 3 February 2026 as " Sangoma FreePBX Improper Authentication Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 24 February 2026.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://community.freepbx.org/t/freepbx-security-vulnerability-sec-2019-001/62772 | Vendor Advisory |
| https://pastebin.com/2CdsQMKW | Broken Link |
| https://wiki.freepbx.org/display/FOP/2019-11-20+Remote+Admin+Authentication+Bypass | Vendor Advisory |
| https://www.freepbx.org/category/blog/ | Product |
| https://community.freepbx.org/t/freepbx-security-vulnerability-sec-2019-001/62772 | Vendor Advisory |
| https://pastebin.com/2CdsQMKW | Broken Link |
| https://wiki.freepbx.org/display/FOP/2019-11-20+Remote+Admin+Authentication+Bypass | Vendor Advisory |
| https://www.freepbx.org/category/blog/ | Product |
| https://research.checkpoint.com/2020/inj3ctor3-operation-leveraging-asterisk-servers-for-monetization/ | ExploitThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-19006 | US Government Resource |
Track CVE-2019-19006 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-19006), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.