Path traversal in Asterisk Open Source and Certified Asterisk - CVE-2026-57200

 

Path traversal in Asterisk Open Source and Certified Asterisk - CVE-2026-57200

Published: June 26, 2026


Vulnerability identifier: #VU135556
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-57200
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute write operations and conditionally execute arbitrary code.

The vulnerability exists due to improper access control and path traversal in the ARI REST-over-WebSocket feature when handling authenticated WebSocket requests. A remote user can send crafted requests to load an arbitrary module path and execute write operations and conditionally execute arbitrary code.

The Asterisk HTTP web server must be enabled, and the attacker must be able to connect to it. The issue affects read-only ARI credentials.


Affected software

Asterisk Open Source
Certified Asterisk

How to mitigate CVE-2026-57200

Install security update from vendor's website.

Asterisk Open Source - addressed in versions 20.20.1, 21.12.3, 22.10.1, 23.4.1
Certified Asterisk - addressed in versions 20.7-cert11, 22.8-cert3

External References

Related Security Bulletins