Description
Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.3, PERM_READ access was sufficient to call fm_list_managers, fm_list_pinsets, fm_show_context, fm_get_mcp_config, fm_backup_status, fm_whos_calling, fm_run_saved_query, and fm_diagnose_trunk, exposing AMI manager secrets, outbound dial PINs, full Asterisk dialplan context, root SSH connection commands, backup artifact paths, CDR history, arbitrary saved GraphQL query execution, and raw AMI endpoint dumps containing SIP fields such as password, md5_cred, and oauth_secret. This issue is fixed in version 1.6.3.
Published: 2026-07-16
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Frogman, a headless PBX control platform, allowed any user with PERM_READ permissions to invoke privileged commands such as fm_list_managers and fm_get_mcp_config. These commands exposed Asterisk Manager Interface secrets, outbound dial PINs, full dialplan context, root SSH command aliases, backup artifact paths, call detail records, and the raw AMI endpoint. In addition, attackers could execute arbitrary GraphQL queries, granting them the ability to run any query supported by the backend. The result is a serious breach of confidentiality.

Affected Systems

The affected product is Frogman, developed by mwtcmi. Versions prior to 1.6.3 are vulnerable. No other vendors are listed.

Risk and Exploitability

The vulnerability carries a CVSS score of 9.3, indicating critical severity. The EPSS score is less than 1 %, suggesting a low probability of exploitation at present, and the vulnerability is not yet listed in CISA’s KEV catalog. Attackers would need an account with PERM_READ rights; from there, they can call the exposed read‑tier endpoints to harvest credentials and execute arbitrary GraphQL queries. Because the vulnerability exists at the API layer, it can be leveraged remotely unless network or RBAC restrictions prevent access.

Generated by OpenCVE AI on July 31, 2026 at 01:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Frogman to version 1.6.3 or later.
  • Restrict PERM_READ access to only trusted users or services.
  • Review and enforce RBAC policies to limit exposure of sensitive read‑tier tools.

Generated by OpenCVE AI on July 31, 2026 at 01:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Mwtcmi
Mwtcmi frogman
Vendors & Products Mwtcmi
Mwtcmi frogman

Thu, 16 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 16 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Description Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.3, PERM_READ access was sufficient to call fm_list_managers, fm_list_pinsets, fm_show_context, fm_get_mcp_config, fm_backup_status, fm_whos_calling, fm_run_saved_query, and fm_diagnose_trunk, exposing AMI manager secrets, outbound dial PINs, full Asterisk dialplan context, root SSH connection commands, backup artifact paths, CDR history, arbitrary saved GraphQL query execution, and raw AMI endpoint dumps containing SIP fields such as password, md5_cred, and oauth_secret. This issue is fixed in version 1.6.3.
Title Frogman: Multiple read-tier tools expose admin-grade data and arbitrary GraphQL execution
Weaknesses CWE-862
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-07-16T18:29:28.728Z

Reserved: 2026-05-14T19:12:32.754Z

Link: CVE-2026-46515

cve-icon Vulnrichment

Updated: 2026-07-16T18:29:25.574Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T01:30:05Z

Weaknesses