LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-46513

Published
CVSS7.4
Severityhigh
WeaknessCWE-256
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Description

Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.2, Frogman stored API tokens generated by Tools/CreateApiToken.php:33-36 as raw bin2hex(random_bytes(32)) strings in oc_api_tokens, and Frogman.class.php:78 authenticated the X-Frogman-Token header by comparing it with the stored raw value, allowing database read access to recover reusable active tokens at their assigned permission level, including admin. This issue is fixed in version 1.6.2.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-46513

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-46513.