CVE-2026-46512
A critical flaw in Frogman PBX allows attackers to inject arbitrary Asterisk commands via the HTTP API, potentially giving them full control over the system.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Users running Frogman PBX versions earlier than 1.6.2.
Real-world impact
An attacker could execute arbitrary shell commands, modify dialplan settings, or take the PBX offline, leading to loss of service and data compromise.
Why this severity
The CVSS score is high because the vulnerability can be exploited over the network with low effort, requires only a user with permission to write to the dialplan, and changes the scope of the system, giving attackers full confidentiality, integrity, and availability impact.
What to do about it
- 011. Check the current Frogman PBX version.
- 022. Download and install Frogman version 1.6.2 or later.
- 033. Restart the PBX service to apply the update.
NVD-referenced vendor advisory
Timeline
- Jul 16, 2026 · 17d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 19, 2026 · 15d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.