Description
Sangoma FreePBX 115.0.16.26 and below, 14.0.13.11 and below, 13.0.197.13 and below have Incorrect Access Control.
CISA Known Exploited Vulnerability
Date added 2026-02-03 | Due date 2026-02-24
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
References
www.freepbx.org/category/blog/
wiki.freepbx.org/...11-20+Remote+Admin+Authentication+Bypass
community.freepbx.org/...ty-vulnerability-sec-2019-001/62772
research.checkpoint.com/...sterisk-servers-for-monetization/
www.cisa.gov/...erabilities-catalog?field_cve=CVE-2019-19006
www.freepbx.org/category/blog/
wiki.freepbx.org/...11-20+Remote+Admin+Authentication+Bypass
community.freepbx.org/...ty-vulnerability-sec-2019-001/62772