Skip to content
COOEY

FAIL › dossier

FreePBX

PRODUCT

· dossier confidence 50%

PROFILE
CategoryVoIP SoftwareWhat they doFreePBX is an open-source IP PBX software platform released under the GNU General Public License. It is designed to allow users to create and configure their own phone system.
SECURITY POSTURE

FreePBX has been subject to multiple high and critical security vulnerabilities, indicating potential weaknesses in its security posture.

Notable failures
  • CVE-2025-57819: High [RCE] - Unpatched RCE allowing unauthenticated access to Admin leading to remote code execution
  • CVE-2025-64328: High [RCE] - OS Command Injection Vulnerability exploited post-authentication
  • CVE-2019-19006: High [RCE] - Exposed to unauthorized access due to improper authentication
  • CVE-2026-46376: Critical - FreePBX is an open-source IP PBX. From 15.0.42 to before 16.0.45 and 17.0.7, unpatched vulnerabilities were present.
Patterns: Repeated unpatched RCE vulnerabilities; Post-authentication OS command injection; Improper authentication leading to unauthorized access
FAILURE HISTORY · 4
DATEEVENTSEVSUMMARY
2025-08-29 CVE-2025-57819 high Sangoma FreePBX had unpatched RCE allowing unauth'd access to Admin leading to remote code execution
2026-02-03 CVE-2025-64328 high Sangoma FreePBX OS Command Injection Vulnerability exploited post-authentication
2026-02-03 CVE-2019-19006 high Sangoma FreePBX exposed to unauthorized access due to improper authentication
2026-05-29 CVE-2026-46376 critical CVE-2026-46376: FreePBX is an open source IP PBX. From 15.0.42 to before 16.0.45 and 17.0.7, una
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-26 03:43:43.133210+00:00