top of page
perceptive_background_267k.jpg

Sangoma FreePBX contains an improper authentication vulnerability that potentially allows unauthorized users to bypass password authentication and access servic…

Published:

3 februari 2026 om 00:00:00

Alert date:

3 februari 2026 om 16:03:37

Source:

cisa.gov

Click to open the original link from this advisory

Identity & Access, Enterprise Applications

CVE-2019-19006 is a critical improper authentication vulnerability in Sangoma FreePBX that allows unauthorized users to bypass password authentication and gain access to FreePBX admin services. This vulnerability enables remote attackers to access administrative functions without proper credentials, potentially leading to complete system compromise. The vulnerability affects the authentication mechanism of FreePBX, a popular open-source PBX system. CISA has documented this vulnerability with a high criticality rating due to the potential for administrative access bypass. The vulnerability was disclosed on November 20, 2019, with documentation available through the FreePBX wiki and the National Vulnerability Database.

Technical details

Mitigation steps:

Affected products:

Sangoma FreePBX

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page