CVE-2019-19006: Sangoma FreePBX Improper Authentication Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2026-02-03. EPSS: 55.9% chance of exploitation in the next 30 days.

Sangoma FreePBX 115.0.16.26 and below, 14.0.13.11 and below, 13.0.197.13 and below have Incorrect Access Control.

Affected products

  • Sangoma FreePBX: from 13.0.0.0, up to and including 13.0.197.13; from 14.0.0.0, up to and including 14.0.13.11; from 15.0.0.0, up to and including 15.0.16.26

Published 2019-11-21. Last modified 2026-06-17.