February 3, 2026 · Applied Cybernetics Group
CVE-2019-19006 — Sangoma FreePBX
Sangoma FreePBX Improper Authentication Vulnerability
- Added to KEV
2026-02-03- Federal due date
2026-02-24- Vendor
- Sangoma
- Product
- FreePBX
- EPSS
- 95.8th percentile (score 0.216, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Unknown
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2019-19006
CISA short description
Sangoma FreePBX contains an improper authentication vulnerability that potentially allows unauthorized users to bypass password authentication and access services provided by the FreePBX admin.
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.