Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-46512: Frogman: Malicious code injected into Asterisk configuration

CVE-2026-46512 CVE-2026-46512
Summary

A bug in Frogman allowed attackers with special permissions to inject malicious code into the Asterisk configuration, potentially allowing them to control the phone system. This issue has been fixed in version 1.6.2, so users should update to this version to stay secure. Update your Frogman installation as soon as possible to prevent potential security risks.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
mwtcmi frogman < 1.6.2
Original title
Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.2, fm_dialplan_apply accepted template parameters including greeting, dest, url, extension, code, and file, and Tools/Di...
Original description
Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.2, fm_dialplan_apply accepted template parameters including greeting, dest, url, extension, code, and file, and Tools/DialplanApply.php wrote Dialplan/Templates.php output to extensions_custom.conf while only Dialplan/TemplateBase.php:38-42 sanitized contextName(), allowing a PERM_WRITE caller using confirm:true to inject arbitrary Asterisk directives such as System(), Set(SHELL(...)), Goto, or Macro. This issue is fixed in version 1.6.2.
mitre CVSS3.1 9.9
Vulnerability type
CWE-94 Code Injection
Published: 16 Jul 2026 · Updated: 18 Jul 2026 · First seen: 16 Jul 2026