Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-46515: Frogman: Unauthorized access to sensitive PBX data

CVE-2026-46515 CVE-2026-46515
Summary

An outdated version of Frogman allows unauthorized access to sensitive PBX data. This includes secrets, passwords, and configuration settings. Update to the latest version, 1.6.3, to fix this issue.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
mwtcmi frogman < 1.6.3
Original title
Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.3, PERM_READ access was sufficient to call fm_list_managers, fm_list_pinsets, fm_show_context, fm_get_mcp_config, fm_bac...
Original description
Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.3, PERM_READ access was sufficient to call fm_list_managers, fm_list_pinsets, fm_show_context, fm_get_mcp_config, fm_backup_status, fm_whos_calling, fm_run_saved_query, and fm_diagnose_trunk, exposing AMI manager secrets, outbound dial PINs, full Asterisk dialplan context, root SSH connection commands, backup artifact paths, CDR history, arbitrary saved GraphQL query execution, and raw AMI endpoint dumps containing SIP fields such as password, md5_cred, and oauth_secret. This issue is fixed in version 1.6.3.
Vulnerability type
CWE-862 Missing Authorization
Published: 16 Jul 2026 · Updated: 29 Jul 2026 · First seen: 16 Jul 2026