FreePBX is an open-source IP phone management system by Sangoma, encompassing VOIP management, call forwarding, conferencing features, and more. Recently, FreePBX released a critical security advisory, stating that the FreePBX Endpoint Manager module contains an authentication bypass vulnerability (CVE-2025-66039, CVSS 4.x: 9.3). If the authentication type is set to “webserver”, the module allows for authentication bypass; if the value of the Authorization header is arbitrary, the session will be directed to the target user regardless of whether the credentials are valid.