top of page
perceptive_background_267k.jpg

Sangoma FreePBX contains an improper authentication vulnerability that potentially allows unauthorized users to bypass password authentication and access servic…

Published:

3 February 2026 at 00:00:00

Alert date:

3 February 2026 at 16:03:37

Source:

cisa.gov

Click to open the original link from this advisory

Identity & Access, Enterprise Applications

CVE-2019-19006 is a critical improper authentication vulnerability in Sangoma FreePBX that allows unauthorized users to bypass password authentication and gain access to FreePBX admin services. This vulnerability enables remote attackers to access administrative functions without proper credentials, potentially leading to complete system compromise. The vulnerability affects the authentication mechanism of FreePBX, a popular open-source PBX system. CISA has documented this vulnerability with a high criticality rating due to the potential for administrative access bypass. The vulnerability was disclosed on November 20, 2019, with documentation available through the FreePBX wiki and the National Vulnerability Database.

Technical details

Mitigation steps:

Affected products:

Sangoma FreePBX

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page