Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-46515: Frogman: Unauthorized access to sensitive PBX data
CVE-2026-46515
CVE-2026-46515
Summary
An outdated version of Frogman allows unauthorized access to sensitive PBX data. This includes secrets, passwords, and configuration settings. Update to the latest version, 1.6.3, to fix this issue.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| mwtcmi | frogman | < 1.6.3 |
Original title
Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.3, PERM_READ access was sufficient to call fm_list_managers, fm_list_pinsets, fm_show_context, fm_get_mcp_config, fm_bac...
Original description
Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.3, PERM_READ access was sufficient to call fm_list_managers, fm_list_pinsets, fm_show_context, fm_get_mcp_config, fm_backup_status, fm_whos_calling, fm_run_saved_query, and fm_diagnose_trunk, exposing AMI manager secrets, outbound dial PINs, full Asterisk dialplan context, root SSH connection commands, backup artifact paths, CDR history, arbitrary saved GraphQL query execution, and raw AMI endpoint dumps containing SIP fields such as password, md5_cred, and oauth_secret. This issue is fixed in version 1.6.3.
Vulnerability type
CWE-862
Missing Authorization
- https://github.com/mwtcmi/frogman/security/advisories/GHSA-q4c4-5cr4-8q47 x_refsource_CONFIRM
- https://github.com/mwtcmi/frogman/issues/13 x_refsource_MISC
- https://github.com/mwtcmi/frogman/issues/25 x_refsource_MISC
- https://github.com/mwtcmi/frogman/commit/55ea257d5c24bc01c814a607faa7e76e86b111e... x_refsource_MISC
- https://github.com/mwtcmi/frogman/commit/b8a8bfc12b564bcb77caef952873b9ffd4a98b0... x_refsource_MISC
- https://github.com/mwtcmi/frogman/releases/tag/v1.6.3 x_refsource_MISC
Published: 16 Jul 2026 · Updated: 29 Jul 2026 · First seen: 16 Jul 2026