PT-2026-60546 · Frogman · Frogman

CVE-2026-46513

·

Published

2026-07-16

·

Updated

2026-07-16

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Frogman versions prior to 1.6.2
Description Frogman provides headless PBX control through MCP and HTTP API. The software stores API tokens generated by the CreateApiToken.php function as raw strings in the oc api tokens table. The Frogman.class.php function authenticates the X-Frogman-Token header by comparing it with these stored raw values. This allows an attacker with database read access to recover active tokens and gain unauthorized access at the assigned permission level, including administrative privileges.
Recommendations Update to version 1.6.2.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-46513
GHSA-9XF5-9GHQ-P6CW

Affected Products

Frogman