Sangoma FreePBX Authentication Bypass Vulnerability
On Track
Sangoma / FreePBX
CWE-89
CWE-288
Description
Sangoma FreePBX contains an authentication bypass vulnerability due to insufficiently sanitized user-supplied data allows unauthenticated access to FreePBX Administrator leading to arbitrary database manipulation and remote code execution.
Required Action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
References
Additional Information
- Catalog Version
- 2025.08.29
- Catalog Released
- Aug. 29, 2025
- Days Until Due
- 10 days
- Last Updated
- 1 week, 3 days ago