PT-2026-60548 · Frogman · Frogman
CVE-2026-46515
·
Published
2026-07-16
·
Updated
2026-07-16
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Frogman versions prior to 1.6.3
Description
Frogman provides headless PBX control through MCP and HTTP API. Users with PERM READ access can call several functions, including
fm list managers(), fm list pinsets(), fm show context(), fm get mcp config(), fm backup status(), fm whos calling(), fm run saved query(), and fm diagnose trunk(). This leads to the exposure of AMI manager secrets, outbound dial PINs, full Asterisk dialplan context, root SSH connection commands, backup artifact paths, and CDR history. Additionally, it allows arbitrary saved GraphQL query execution and raw AMI endpoint dumps containing SIP fields such as password, md5 cred, and oauth secret.Recommendations
Update to version 1.6.3.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Frogman