CVE-2026-23741 | Asterisk PBX up to 20.7-cert8/20.18.1/21.12.0/22.8.1/23.2.1 ast_coredumper uncontrolled search path (GHSA-rvch-3jmx-3jf3 / WID-SEC-2026-0327)
A vulnerability described as problematic has been identified in Asterisk PBX up to 20.7-cert8/20.18.1/21.12.0/22.8.1/23.2.1. Affected is an unknown function of the file asterisk/contrib/scripts/ast_coredumper. The manipulation results in uncontrolled search path.
This vulnerability is identified as CVE-2026-23741. The attack is only possible with local access. There is not any exploit available.
Upgrading the affected component is recommended.