CVE-2026-46515
A security flaw in Frogman's PBX control system allows users with basic read permissions to access highly sensitive information. This data includes administrative secrets, connection commands, and private communication details.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Users of Frogman PBX control software prior to version 1.6.3.
Real-world impact
An attacker with minimal access could steal administrative credentials, SSH commands, and private call history, potentially leading to a full takeover of the phone system's configuration and communication data.
Why this severity
The critical score reflects that an attacker can remotely exploit this vulnerability with low complexity to gain access to highly sensitive system secrets and configuration data.
What to do about it
- 01Upgrade Frogman to version 1.6.3 or later.
NVD-referenced vendor advisory
Timeline
- Jul 16, 2026 · 17d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 19, 2026 · 15d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.