Insecure library loading in Asterisk Open Source and Certified Asterisk - CVE-2026-23740
Published: February 6, 2026
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to the application loads dynamic libraries in an insecure manner from the /tmp directory. A local user can place a specially crafted library file into the /tmp directory and execute arbitrary code on the system with root privileges.
Affected software
Certified Asterisk
How to mitigate CVE-2026-23740
Certified Asterisk - update to 20.7-cert9