Arbitrary File Overwrite Vulnerability in Asterisk Telephony Toolkit
CVE-2026-23740
What is CVE-2026-23740?
Asterisk, an open source private branch exchange and telephony toolkit, is exposed to a vulnerability allowing an attacker to execute arbitrary commands. This occurs when the 'ast_coredumper' component writes its gdb initialization and output files to a world-writable directory, such as '/tmp'. Due to lax permissions, any user on a Linux system can manipulate these files to gain unauthorized access, potentially resulting in the execution of malicious commands. This vulnerability has been addressed in various patches, including versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
asterisk < 23.2.2 < 23.2.2
asterisk < 22.8.2 < 22.8.2
asterisk < 21.12.1 < 21.12.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
