CVE-2023-43336: Sangoma FreePBX

High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.

Sangoma Technologies FreePBX before cdr 15.0.18, 16.0.40, 15.0.16, and 16.0.17 was discovered to contain an access control issue via a modified parameter value, e.g., changing extension=self to extension=101.

Affected products

  • Sangoma FreePBX: before 15.0.16 (fixed in 15.0.16); from 16.0.2, before 16.0.17 (fixed in 16.0.17); before 15.0.18 (fixed in 15.0.18); from 16.0.2, before 16.0.40 (fixed in 16.0.40)

Published 2023-11-02. Last modified 2026-07-09.