Arbitrary Code Injection in Frogman Headless PBX Control
CVE-2026-46512

9.9CRITICAL

Key Information:

Vendor

Mwtcmi

Status
Vendor
CVE Published:
16 July 2026

What is CVE-2026-46512?

Frogman, a headless PBX control tool, allows remote manipulation through its MCP and HTTP API interfaces. Prior to version 1.6.2, a vulnerability existed where the fm_dialplan_apply method improperly handled template parameters. This oversight permitted attackers to inject arbitrary Asterisk directives by exploiting the insufficient sanitization of certain function parameters. As a result, malicious actors could potentially execute harmful commands on the system, heightening security risks. The issue has been addressed in version 1.6.2, which includes necessary protections against such exploits.

Affected Version(s)

frogman < 1.6.2

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.