CVE-2019-19006
sangoma freepbx
Published 21 Nov 2019 · updated 17 Jun 2026 · Analyzed
9.8 Critical · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 3 Feb 2026, with a remediation deadline of 24 Feb 2026 for US federal agencies.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Description
Sangoma FreePBX 115.0.16.26 and below, 14.0.13.11 and below, 13.0.197.13 and below have Incorrect Access Control.
References
- community.freepbx.org/t/freepbx-security-vulnerability-sec-2019-001/62772 · Vendor Advisory
- pastebin.com/2CdsQMKW · Broken Link
- wiki.freepbx.org/display/FOP/2019-11-20+Remote+Admin+Authentication+Bypass · Vendor Advisory
- www.freepbx.org/category/blog/ · Product
- research.checkpoint.com/2020/inj3ctor3-operation-leveraging-asterisk-servers-for-monetization/ · Exploit, Third Party Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-19006 · US Government Resource