Executive brief
Sangoma FreePBX, a widely used open-source communication platform for managing VoIP phone systems, contains a critical security flaw. This vulnerability allows an unauthorized person to bypass the login screen and gain full administrative access to the system over the internet. An attacker could take control of the phone system, intercept calls, or disrupt business communications.
Technical details
An improper authentication vulnerability (CWE-287) exists in Sangoma FreePBX versions 13, 14, and 15. The flaw allows a remote, unauthenticated attacker to bypass the administrative login mechanism via the network without any user interaction. Successful exploitation grants the attacker full administrative privileges over the FreePBX web interface. This vulnerability has been observed being exploited in the wild to compromise Asterisk-based servers. Users should update to versions above 15.0.16.26, 14.0.13.11, or 13.0.197.13 as appropriate.
Affected products
- Sangoma FreePBX 15.0.16.26 and below, 14.0.13.11 and below, 13.0.197.13 and below
Timeline
- 2019-11-20: advisory: Vendor security advisory published
- 2020-08-24: other: CWE classification updated by NIST
- 2026-02-03: kev added: Added to CISA Known Exploited Vulnerabilities catalog