CVE-2026-46515
CRITICALFrogman: Multiple read-tier tools expose admin-grade data and arbitrary GraphQL execution
Title source: cnaDescription
Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.3, PERM_READ access was sufficient to call fm_list_managers, fm_list_pinsets, fm_show_context, fm_get_mcp_config, fm_backup_status, fm_whos_calling, fm_run_saved_query, and fm_diagnose_trunk, exposing AMI manager secrets, outbound dial PINs, full Asterisk dialplan context, root SSH connection commands, backup artifact paths, CDR history, arbitrary saved GraphQL query execution, and raw AMI endpoint dumps containing SIP fields such as password, md5_cred, and oauth_secret. This issue is fixed in version 1.6.3.
References (6)
Core 6
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/mwtcmi/frogman/security/advisories/GHSA-q4c4-5cr4-8q47
X_Refsource_Misc x_refsource_misc
https://github.com/mwtcmi/frogman/issues/13
X_Refsource_Misc x_refsource_misc
https://github.com/mwtcmi/frogman/issues/25
X_Refsource_Misc x_refsource_misc
https://github.com/mwtcmi/frogman/commit/55ea257d5c24bc01c814a607faa7e76e86b111ec
X_Refsource_Misc x_refsource_misc
https://github.com/mwtcmi/frogman/commit/b8a8bfc12b564bcb77caef952873b9ffd4a98b00
X_Refsource_Misc x_refsource_misc
https://github.com/mwtcmi/frogman/releases/tag/v1.6.3
Scores
CVSS v4
9.3
EPSS
0.0032
EPSS Percentile
24.8%
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-862
Status
published
Products (1)
mwtcmi/frogman
< 1.6.3
Published
Jul 16, 2026
Tracked Since
Jul 17, 2026