


Perceptive Security
SOC/SIEM Consultancy

Sangoma FreePBX contains an improper authentication vulnerability that potentially allows unauthorized users to bypass password authentication and access servic…
Published:
3 February 2026 at 00:00:00
Alert date:
3 February 2026 at 16:03:37
Source:
cisa.gov
Identity & Access, Enterprise Applications
CVE-2019-19006 is a critical improper authentication vulnerability in Sangoma FreePBX that allows unauthorized users to bypass password authentication and gain access to FreePBX admin services. This vulnerability enables remote attackers to access administrative functions without proper credentials, potentially leading to complete system compromise. The vulnerability affects the authentication mechanism of FreePBX, a popular open-source PBX system. CISA has documented this vulnerability with a high criticality rating due to the potential for administrative access bypass. The vulnerability was disclosed on November 20, 2019, with documentation available through the FreePBX wiki and the National Vulnerability Database.
Technical details
Mitigation steps:
Affected products:
Sangoma FreePBX
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2019-19006
https://wiki.freepbx.org/display/FOP/2019-11-20%2BRemote%2BAdmin%2BAuthentication%2BBypass
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
