PT-2026-60545 · Frogman+1 · Frogman+1

CVE-2026-46512

·

Published

2026-07-16

·

Updated

2026-07-17

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Frogman versions prior to 1.6.2
Description Frogman provides headless PBX control through MCP and HTTP API. The fm dialplan apply function accepts template parameters including greeting, dest, url, extension, code, and file. Because Tools/DialplanApply.php writes Dialplan/Templates.php output to extensions custom.conf and only Dialplan/TemplateBase.php sanitizes contextName(), a caller with PERM WRITE permissions using confirm:true can inject arbitrary Asterisk directives, such as System(), Set(SHELL(...)), Goto, or Macro.
Recommendations Update to version 1.6.2.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-46512
GHSA-PXFC-Q72V-JH8M

Affected Products

Asterisk
Frogman