CVE-2026-23740
Unknown
Unknown - Not Provided
Arbitrary Command Execution via World-Writable Directory in Asterisk
Publication date: 2026-02-06
Last updated on: 2026-02-10
Assigner: GitHub, Inc.
Description
Description
Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2, when ast_coredumper writes its gdb init and output files to a directory that is world-writable (for example /tmp), an attacker with write permission(which is all users on a linux system) to that directory can cause root to execute arbitrary commands or overwrite arbitrary files by controlling the gdb init file and output paths. This issue has been patched in versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| sangoma | certified_asterisk | 18.9 |
| sangoma | certified_asterisk | 18.9 |
| sangoma | certified_asterisk | 18.9 |
| sangoma | certified_asterisk | 18.9 |
| sangoma | certified_asterisk | 18.9 |
| sangoma | certified_asterisk | 13.13.0 |
| sangoma | certified_asterisk | 13.13.0 |
| sangoma | certified_asterisk | 13.13.0 |
| sangoma | certified_asterisk | 13.13.0 |
| sangoma | certified_asterisk | 13.13.0 |
| sangoma | certified_asterisk | 13.13.0 |
| sangoma | certified_asterisk | 13.13.0 |
| sangoma | certified_asterisk | 13.13.0 |
| sangoma | certified_asterisk | 13.13.0 |
| sangoma | certified_asterisk | 16.8.0 |
| sangoma | certified_asterisk | 16.8.0 |
| sangoma | certified_asterisk | 16.8.0 |
| sangoma | certified_asterisk | 16.8.0 |
| sangoma | certified_asterisk | 16.8.0 |
| sangoma | certified_asterisk | 16.8.0 |
| sangoma | certified_asterisk | 16.8.0 |
| sangoma | certified_asterisk | 16.8.0 |
| sangoma | certified_asterisk | 16.8.0 |
| sangoma | certified_asterisk | 16.8.0 |
| sangoma | certified_asterisk | 16.8.0 |
| sangoma | certified_asterisk | 16.8.0 |
| sangoma | certified_asterisk | 16.8.0 |
| sangoma | certified_asterisk | 18.9 |
| sangoma | certified_asterisk | 18.9 |
| sangoma | certified_asterisk | 18.9 |
| sangoma | certified_asterisk | 18.9 |
| sangoma | certified_asterisk | 18.9 |
| sangoma | certified_asterisk | 18.9 |
| sangoma | certified_asterisk | 18.9 |
| sangoma | certified_asterisk | 18.9 |
| sangoma | certified_asterisk | 18.9 |
| sangoma | certified_asterisk | 18.9 |
| sangoma | certified_asterisk | 18.9 |
| sangoma | certified_asterisk | 18.9 |
| sangoma | certified_asterisk | 20.7 |
| sangoma | certified_asterisk | 20.7 |
| sangoma | certified_asterisk | 20.7 |
| sangoma | certified_asterisk | 20.7 |
| sangoma | certified_asterisk | 20.7 |
| sangoma | certified_asterisk | 20.7 |
| sangoma | certified_asterisk | 20.7 |
| sangoma | certified_asterisk | 20.7 |
| sangoma | certified_asterisk | 18.9 |
| sangoma | certified_asterisk | 18.9 |
| sangoma | certified_asterisk | 18.9 |
| sangoma | certified_asterisk | 16.8 |
| sangoma | certified_asterisk | 16.8 |
| sangoma | certified_asterisk | 16.8 |
| sangoma | certified_asterisk | 16.8 |
| sangoma | certified_asterisk | 16.8 |
| sangoma | certified_asterisk | 16.8 |
| sangoma | certified_asterisk | 16.8 |
| sangoma | certified_asterisk | 16.8 |
| sangoma | certified_asterisk | 16.8 |
| sangoma | certified_asterisk | 16.8 |
| sangoma | certified_asterisk | 16.8 |
| sangoma | certified_asterisk | 16.8 |
| sangoma | certified_asterisk | 16.8 |
| sangoma | certified_asterisk | 16.8 |
| sangoma | certified_asterisk | 20.7 |
| sangoma | certified_asterisk | 13.13.0 |
| sangoma | asterisk | to 20.18.2 (exc) |
| sangoma | asterisk | From 21.0.0 (inc) to 21.12.1 (exc) |
| sangoma | asterisk | From 22.0.0 (inc) to 22.8.2 (exc) |
| sangoma | asterisk | From 23.0.0 (inc) to 23.2.2 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-427 | The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors. |