Skip to content
COOEY

EXPOSURES › CVE-2019-19006

CVE-2019-19006

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2026-02-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2019-19006 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatchedrce

Sangoma FreePBX exposed to unauthorized access due to improper authentication

Sangoma's FreePBX suffered an unpatched vulnerability allowing unauthorized users to bypass authentication, potentially compromising PBX services.

Shame score — Critical unpatched RCE in a widely-used VoIP system.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Sangoma FreePBX contains an improper authentication vulnerability that potentially allows unauthorized users to bypass password authentication and access services provided by the FreePBX admin.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.