CVE-2026-46515 Details
Description
Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.3, PERM_READ access was sufficient to call fm_list_managers, fm_list_pinsets, fm_show_context, fm_get_mcp_config, fm_backup_status, fm_whos_calling, fm_run_saved_query, and fm_diagnose_trunk, exposing AMI manager secrets, outbound dial PINs, full Asterisk dialplan context, root SSH connection commands, backup artifact paths, CDR history, arbitrary saved GraphQL query execution, and raw AMI endpoint dumps containing SIP fields such as password, md5_cred, and oauth_secret. This issue is fixed in version 1.6.3.
A vulnerability in Frogman prior to version 1.6.3 allows authenticated users with PERM_READ access to access sensitive administrative data and functionalities. This includes AMI manager credentials, outbound dial PINs, the full Asterisk dialplan context, root SSH commands, backup artifact paths, CDR history, and the execution of arbitrary saved GraphQL queries. The issue arises because certain tools were accessible at a read-only permission level, enabling low-tier users to retrieve confidential information and perform actions meant for higher-level access.
Users can update to Frogman version 1.6.3, where this vulnerability has been patched. Instructions for updating are available in the Frogman GitHub repository.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 16, 2026CISA-ADP
Assessed Jul 16, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/mwtcmi/frogman/commit/55ea257d5c24bc01c814a607faa7e76e86b111ec | [email protected] | Source CodeVendor |
| https://github.com/mwtcmi/frogman/commit/b8a8bfc12b564bcb77caef952873b9ffd4a98b00 | [email protected] | Source CodeVendor |
| https://github.com/mwtcmi/frogman/issues/13 | [email protected] | Issue TrackingTechnical DescriptionVendor |
| https://github.com/mwtcmi/frogman/issues/25 | [email protected] | Issue TrackingTechnical DescriptionVendor |
| https://github.com/mwtcmi/frogman/releases/tag/v1.6.3 | [email protected] | Release NotesVendor |
| https://github.com/mwtcmi/frogman/security/advisories/GHSA-q4c4-5cr4-8q47 | [email protected] | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Frogman | <= 1.6.2 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 16, 2026 | New CVE Received | [email protected] |
| Jul 16, 2026 | CVE Modified | CISA-ADP |
Volerion