Untrusted search path in Asterisk Open Source and Certified Asterisk - CVE-2026-57203
Published: June 26, 2026
Asterisk Open Source
Certified Asterisk
Detailed vulnerability description
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to untrusted search path in the ast_loggrabber script when executing a python script from the /tmp directory. A local user can place a malicious script in /tmp to escalate privileges.
Exploitation requires prior shell access on the Asterisk server and an administrator to run the ast_loggrabber script with elevated privileges.