CVE-2019-19006CISA KEVEPSS p98.3%

CVE-2019-19006 Sangoma FreePBX Improper Authentication Vulnerability

Sangoma / FreePBX

Description

Sangoma FreePBX contains an improper authentication vulnerability that potentially allows unauthorized users to bypass password authentication and access services provided by the FreePBX admin.

Scoring

CVSS 9.8 ()
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS36.61% probability of exploitation · percentile 98.3% · 2026-08-03T12:00:16Z
Last modified2026-06-17

CISA KEV entry

Added to KEV: 2026-02-03

(incoming)1

TypeTargetConfidenceTier
KEVEntry Sangoma FreePBX Improper Authentication Vulnerabilitykev-cve-2019-190060%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
Sangoma FreePBX Authentication Bypass Vulnerability
CVE
Sangoma FreePBX OS Command Injection Vulnerability
CVE
CVE-2025-66039
CVE
CVE-2025-32105
CVE
CVE-2026-28284
CVE
CVE-2026-46376
Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.