CVE-2026-23741General(sangoma / asterisk)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2, the asterisk/contrib/scripts/ast_coredumper runs as root, as noted by the NOTES tag on line 689 of the ast_coredumper file. The script will source the contents of /etc/asterisk/ast_debug_tools.conf, which resides in a folder that is writeable by the asterisk user:group. Due to the /etc/asterisk/ast_debug_tools.conf file following bash semantics and it being loaded; an attacker with write permissions may add or modify the file such that when the root ast_coredumper is run; it would source and thereby execute arbitrary bash code found in the /etc/asterisk/ast_debug_tools.conf. This issue has been patched in versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-427

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • asterisk
  • certified_asterisk

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • General: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
asteriskcertified_asterisk

1 version affected across 2 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-06: 102-06
Signal classification1 categories
General
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • CVE@CVEnew
    General

    CVE-2026-23741 Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2, the asterisk/contrib/scr… https://www.cve.org/CVERecord?id=CVE-2026-23741

    Post summary

    The text merely references CVE-2026-23741 and links to the CVE record, providing no further details or actionable information.

    00010124
    56.5K followersView on X
CPE platform detail12 entries

12 of 12 entries

PartVendorProductVersionTarget SWTarget HW
Appsangomaasterisk---
Appsangomacertified_asterisk---
Appsangomacertified_asterisk20.7--
Appsangomacertified_asterisk20.7--
Appsangomacertified_asterisk20.7--
Appsangomacertified_asterisk20.7--
Appsangomacertified_asterisk20.7--
Appsangomacertified_asterisk20.7--
Appsangomacertified_asterisk20.7--
Appsangomacertified_asterisk20.7--
Appsangomacertified_asterisk20.7--
Appsangomacertified_asterisk20.7--

Explore more