PROFILE
CategoryVoIP SoftwareWhat they doFreePBX is an open-source IP PBX software platform released under the GNU General Public License. It is designed to allow users to create and configure their own phone system.
SECURITY POSTURE
FreePBX has been subject to multiple high and critical security vulnerabilities, indicating potential weaknesses in its security posture.
Notable failures
- CVE-2025-57819: High [RCE] - Unpatched RCE allowing unauthenticated access to Admin leading to remote code execution
- CVE-2025-64328: High [RCE] - OS Command Injection Vulnerability exploited post-authentication
- CVE-2019-19006: High [RCE] - Exposed to unauthorized access due to improper authentication
- CVE-2026-46376: Critical - FreePBX is an open-source IP PBX. From 15.0.42 to before 16.0.45 and 17.0.7, unpatched vulnerabilities were present.
Patterns: Repeated unpatched RCE vulnerabilities; Post-authentication OS command injection; Improper authentication leading to unauthorized access
FAILURE HISTORY · 4
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2025-08-29 | CVE-2025-57819 | high | Sangoma FreePBX had unpatched RCE allowing unauth'd access to Admin leading to remote code execution |
| 2026-02-03 | CVE-2025-64328 | high | Sangoma FreePBX OS Command Injection Vulnerability exploited post-authentication |
| 2026-02-03 | CVE-2019-19006 | high | Sangoma FreePBX exposed to unauthorized access due to improper authentication |
| 2026-05-29 | CVE-2026-46376 | critical | CVE-2026-46376: FreePBX is an open source IP PBX. From 15.0.42 to before 16.0.45 and 17.0.7, una |
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-26 03:43:43.133210+00:00