Path traversal in Asterisk Open Source and Certified Asterisk - CVE-2026-57200
Published: June 26, 2026
Vulnerability details
The vulnerability allows a remote user to execute write operations and conditionally execute arbitrary code.
The vulnerability exists due to improper access control and path traversal in the ARI REST-over-WebSocket feature when handling authenticated WebSocket requests. A remote user can send crafted requests to load an arbitrary module path and execute write operations and conditionally execute arbitrary code.
The Asterisk HTTP web server must be enabled, and the attacker must be able to connect to it. The issue affects read-only ARI credentials.
Affected software
Certified Asterisk
How to mitigate CVE-2026-57200
Certified Asterisk - addressed in versions 20.7-cert11, 22.8-cert3