Junglewise Threat Intelligence

CVE-2019-19006: Sangoma FreePBX improper authentication in admin interface

CVE-2019-19006 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2026-02-03

Technologies: Sangoma FreePBX. Vendors: Sangoma.

Executive brief

Sangoma FreePBX, a widely used open-source communication platform for managing VoIP phone systems, contains a critical security flaw. This vulnerability allows an unauthorized person to bypass the login screen and gain full administrative access to the system over the internet. An attacker could take control of the phone system, intercept calls, or disrupt business communications.

Technical details

An improper authentication vulnerability (CWE-287) exists in Sangoma FreePBX versions 13, 14, and 15. The flaw allows a remote, unauthenticated attacker to bypass the administrative login mechanism via the network without any user interaction. Successful exploitation grants the attacker full administrative privileges over the FreePBX web interface. This vulnerability has been observed being exploited in the wild to compromise Asterisk-based servers. Users should update to versions above 15.0.16.26, 14.0.13.11, or 13.0.197.13 as appropriate.

Affected products

  • Sangoma FreePBX 15.0.16.26 and below, 14.0.13.11 and below, 13.0.197.13 and below

Timeline

  • 2019-11-20: advisory: Vendor security advisory published
  • 2020-08-24: other: CWE classification updated by NIST
  • 2026-02-03: kev added: Added to CISA Known Exploited Vulnerabilities catalog

Related threats