#VU122443 Incorrect default permissions in Asterisk Open Source and Certified Asterisk - CVE-2026-23741
Published: February 6, 2026
Asterisk Open Source
Certified Asterisk
Digium (Linux Support Services)
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to incorrect default permissions for the "/etc/asterisk/ast_debug_tools.conf" file, which is writable by the asterisk user:group and is used by the "asterisk/contrib/scripts/ast_coredumper". A local user can modify the file and execute arbitrary OS commands as root.