{"id":"CVE-2019-19006","aliases":[],"url":"https://o3.security/vulnerability/CVE-2019-19006","summary":null,"details":"Sangoma FreePBX 115.0.16.26 and below, 14.0.13.11 and below, 13.0.197.13 and below have Incorrect Access Control.","published":"2019-11-21T18:15:11.993Z","modified":"2026-07-08T05:53:25.114546020Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.36615,"percentile":0.98379,"asOf":"2026-08-27"},"cisaKev":{"dateAdded":"2026-02-03","dueDate":"2026-02-24","knownRansomwareCampaignUse":false},"exploitsKnown":1,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://pastebin.com/2CdsQMKW"},{"type":"WEB","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-19006"},{"type":"ADVISORY","url":"https://community.freepbx.org/t/freepbx-security-vulnerability-sec-2019-001/62772"},{"type":"ADVISORY","url":"https://wiki.freepbx.org/display/FOP/2019-11-20+Remote+Admin+Authentication+Bypass"},{"type":"ARTICLE","url":"https://www.freepbx.org/category/blog/"},{"type":"EVIDENCE","url":"https://research.checkpoint.com/2020/inj3ctor3-operation-leveraging-asterisk-servers-for-monetization/"}],"provenance":{"sources":["OSV.dev","CISA KEV","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T05:53:25.114546020Z"}}