PT-2026-60548 · Frogman · Frogman

CVE-2026-46515

·

Published

2026-07-16

·

Updated

2026-07-16

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Frogman versions prior to 1.6.3
Description Frogman provides headless PBX control through MCP and HTTP API. Users with PERM READ access can call several functions, including fm list managers(), fm list pinsets(), fm show context(), fm get mcp config(), fm backup status(), fm whos calling(), fm run saved query(), and fm diagnose trunk(). This leads to the exposure of AMI manager secrets, outbound dial PINs, full Asterisk dialplan context, root SSH connection commands, backup artifact paths, and CDR history. Additionally, it allows arbitrary saved GraphQL query execution and raw AMI endpoint dumps containing SIP fields such as password, md5 cred, and oauth secret.
Recommendations Update to version 1.6.3.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-46515
GHSA-Q4C4-5CR4-8Q47

Affected Products

Frogman