ZeroHour

CVE-2019-19006

KEV PoC large1

Authentication Bypass in Sangoma FreePBX Admin Interface

CISA: Sangoma FreePBX Improper Authentication Vulnerability

CVSS 3.1
9.8 critical
EPSS
37%p98
Published
()
KEV added
AI analysis

Sangoma FreePBX contains an improper authentication flaw (CWE-287) that potentially allows unauthorized users to bypass password authentication on services provided by the FreePBX admin. An attacker triggers it by sending requests to the FreePBX admin interface without valid credentials, defeating the password check rather than exploiting a code-level bug. Successful exploitation grants unauthorized access to FreePBX administrative services, which can expose PBX configuration and allow management actions under another user's privileges. Any Sangoma FreePBX deployment is affected (CISA lists the affected product as Sangoma FreePBX with no version ranges specified), with risk concentrated on systems whose admin interface is reachable from the internet or untrusted networks. The flaw was added to CISA KEV on 2026-02-03, confirming known in-the-wild exploitation; EPSS estimates a 36.6% chance of exploitation within 30 days (98th percentile), and no public proof-of-concept is known.

What to do: Apply mitigations per vendor instructions as required by CISA KEV, or discontinue use if mitigations are unavailable; federal agencies must follow BOD 22-01 guidance, including for cloud services. Because the flaw bypasses admin authentication, restrict the FreePBX admin interface to trusted networks (VPN or firewall allowlists) and avoid exposing it directly to the internet. Review FreePBX admin access logs for unexpected successful logins or unexplained configuration changes from unknown sources.

Affected
Sangoma FreePBXAffected per CISA as 'Sangoma FreePBX'; no specific version ranges were provided in the available data
Estimated exposure
largetens of thousands of internet-exposed FreePBX admin panels (estimate) — FreePBX is among the most widely deployed open-source Asterisk management front-ends, and public internet scans (e.g., Shodan/Censys) consistently index on the order of tens of thousands of FreePBX admin interfaces exposed online; exact…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Sangoma FreePBX 115.0.16.26 and below, 14.0.13.11 and below, 13.0.197.13 and below have Incorrect Access Control.

CISA Known Exploited Vulnerability
Affected
Sangoma FreePBX
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
sangoma
Products
freepbx
Weakness
CWE-287
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news