Insufficient Granularity of Access Control in Asterisk Open Source and Certified Asterisk - CVE-2026-57202
Published: June 26, 2026
Vulnerability details
The vulnerability allows a remote user to perform unauthorized file writes.
The vulnerability exists due to insufficient granularity of access control in the ARI setChannelVar functionality when handling requests to set channel variables using the FILE() dialplan function. A remote user can send a specially crafted request to perform unauthorized file writes.
The Asterisk HTTP webserver must be enabled, and the issue is reachable only if the attacker can connect to that server. Valid read-only ARI credentials are required.
Affected software
Certified Asterisk
How to mitigate CVE-2026-57202
Certified Asterisk - addressed in versions 20.7-cert11, 22.8-cert3