← Vulnerability feed

Vulnerability record · CVE-2019-19006 · published 21 November 2019

CVE-2019-19006: Sangoma FreePBX improper authentication allows remote admin bypass

Sangoma · Freepbx

FreePBX versions 115.0.16.26, 14.0.13.11, 13.0.197.13 and below contain an incorrect access control flaw (CWE-287 improper authentication) that lets an unauthenticated remote party bypass admin authentication. Because FreePBX is the web management layer for Asterisk-based phone systems, a bypass of this control exposes the full administrative interface.

9.8 CVSS 3.1 Critical CISA KEV since 3 Feb 2026 EPSS 56% · top 1.0% CWE-287 · Improper authentication
9.8CVSS 3.1 base score, v2 7.5
56%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
10References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

Sangoma FreePBX 115.0.16.26 and below, 14.0.13.11 and below, 13.0.197.13 and below have Incorrect Access Control.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or interaction required, active CISA KEV listing and high EPSS score make this an urgent patch-first issue.

What it is

FreePBX versions 115.0.16.26, 14.0.13.11, 13.0.197.13 and below contain an incorrect access control flaw (CWE-287 improper authentication) that lets an unauthenticated remote party bypass admin authentication. Because FreePBX is the web management layer for Asterisk-based phone systems, a bypass of this control exposes the full administrative interface.

Impact

An attacker gains full administrative access to the FreePBX management interface without credentials, with high impact to confidentiality, integrity and availability per the CVSS vector. From there they can reconfigure the PBX, including extensions, trunks and call routing, and potentially pivot into the underlying telephony infrastructure.

Attack surface

Reachable over the network via the FreePBX web interface; the CVSS vector is AV:N/AC:L/PR:N/UI:N, so no authentication and no user interaction are required. The record does not specify the exact endpoint or request used for the bypass.

Exploitation

CVE-2019-19006 is listed in CISA KEV with a due date of 2026-02-24, and EPSS gives a 30-day probability of 0.36615 (98.4th percentile), indicating observed exploitation activity. A third-party research reference is tagged Exploit, and no ransomware campaign use is documented.

What to do

  • Upgrade FreePBX to a release above the affected 115.0.16.26, 14.0.13.11 and 13.0.197.13 branches per the vendor advisory SEC-2019-001.
  • If immediate patching is not possible, restrict management interface access to trusted networks or VPN and follow CISA BOD 22-01 guidance, including discontinuing use if no mitigation is available.
  • Place the FreePBX admin interface behind a reverse proxy or firewall rule that blocks untrusted internet access.
  • Audit FreePBX admin accounts and configuration for unauthorized changes, and rotate credentials and API keys after remediation.
  • Monitor vendor advisories for follow-up fixes, since the record does not enumerate every affected build.

Detection

  • Review FreePBX/Asterisk web server logs for admin interface requests that succeed without a preceding authenticated session or login.
  • Alert on configuration changes to extensions, trunks, outbound routes or admin users made outside change windows.
  • Monitor for unexpected outbound calling or toll fraud patterns from the PBX that could follow an admin compromise.
  • Correlate network access to the FreePBX management port from untrusted source addresses with subsequent admin activity.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2019-19006 to the Known Exploited Vulnerabilities catalog on 3 February 2026 as " Sangoma FreePBX Improper Authentication Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 24 February 2026.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-19006 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-57819FreePBX unauthenticated SQL injection and auth bypass to RCEFreePBX 15, 16 and 17 fail to sanitize user-supplied data, letting an unauthenticated attacker bypass authentication to the FreePBX Administrator int…KEVEPSS 85%analysed10.0CVE-2014-7235Freepbx code injection vulnerabilityhtdocs_ari/includes/login.php in the ARI Framework module/Asterisk Recording Interface (ARI) in FreePBX before 2.9.0.9, 2.10.x, and 2.11 before 2.11.…EPSS 43%9.8CVE-2020-36630Sangoma freepbx sql injection vulnerabilityA vulnerability was found in FreePBX cdr 14.0. It has been classified as critical. This affects the function ajaxHandler of the file ucp/Cdr.class.ph…EPSS 0.68%9.3CVE-2026-46376Sangoma freepbx hard-coded credentials vulnerabilityFreePBX is an open source IP PBX. From 15.0.42 to before 16.0.45 and 17.0.7, unauthenticated users may be able to access the User Control Panel (UCP)…EPSS 0.50%9.3CVE-2025-66039Sangoma freepbx improper authentication vulnerabilityFreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions are vulnerable to authentication bypass when the a…EPSS 3.3%8.8CVE-2023-43336Sangoma freepbx improper access control vulnerabilitySangoma Technologies FreePBX before cdr 15.0.18, 16.0.40, 15.0.16, and 16.0.17 was discovered to contain an access control issue via a modified param…EPSS 0.72%8.7CVE-2024-58294Sangoma freepbx os command injection vulnerabilityFreePBX 16 contains an authenticated remote code execution vulnerability in the API module that allows attackers with valid session credentials to ex…EPSS 3.6%8.6CVE-2026-28287Sangoma freepbx os command injection vulnerabilityFreePBX is an open source IP PBX. From versions 16.0.17.2 to before 16.0.20 and from version 17.0.2.4 to before 17.0.5, multiple command injection vu…EPSS 1.5%

Source: NIST National Vulnerability Database (record CVE-2019-19006), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.