CVE-2019-19006
KEV PoC large1Authentication Bypass in Sangoma FreePBX Admin Interface
CISA: Sangoma FreePBX Improper Authentication Vulnerability
Sangoma FreePBX contains an improper authentication flaw (CWE-287) that potentially allows unauthorized users to bypass password authentication on services provided by the FreePBX admin. An attacker triggers it by sending requests to the FreePBX admin interface without valid credentials, defeating the password check rather than exploiting a code-level bug. Successful exploitation grants unauthorized access to FreePBX administrative services, which can expose PBX configuration and allow management actions under another user's privileges. Any Sangoma FreePBX deployment is affected (CISA lists the affected product as Sangoma FreePBX with no version ranges specified), with risk concentrated on systems whose admin interface is reachable from the internet or untrusted networks. The flaw was added to CISA KEV on 2026-02-03, confirming known in-the-wild exploitation; EPSS estimates a 36.6% chance of exploitation within 30 days (98th percentile), and no public proof-of-concept is known.
What to do: Apply mitigations per vendor instructions as required by CISA KEV, or discontinue use if mitigations are unavailable; federal agencies must follow BOD 22-01 guidance, including for cloud services. Because the flaw bypasses admin authentication, restrict the FreePBX admin interface to trusted networks (VPN or firewall allowlists) and avoid exposing it directly to the internet. Review FreePBX admin access logs for unexpected successful logins or unexplained configuration changes from unknown sources.
| Sangoma FreePBX | Affected per CISA as 'Sangoma FreePBX'; no specific version ranges were provided in the available data |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Sangoma FreePBX 115.0.16.26 and below, 14.0.13.11 and below, 13.0.197.13 and below have Incorrect Access Control.
- Affected
- Sangoma FreePBX
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- sangoma
- Products
- freepbx
- Weakness
- CWE-287
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H