← Back to browse · API

CVE-2019-19006

Severity
CRITICAL
CVSS
9.8
EPSS
0.36615
Risk score
77.02
CISA KEV
Yes
PoC
No
Published
2026-02-03
Modified
2026-02-03
First seen
2026-08-07
Aliases
EUVD-2019-8659, GHSA-85H5-CHMW-697J
Products
Sangoma:FreePBX, n/a:n/a n/a
Sources
euvd EUVD-2019-8659
cisa.gov CVE-2019-19006

Description

Sangoma FreePBX contains an improper authentication vulnerability that potentially allows unauthorized users to bypass password authentication and access services provided by the FreePBX admin.

References