{"id":"CVE-2026-23741","summary":"ast_coredumper running as root sources ast_debug_tools.conf from /etc/asterisk; potentially leading to privilege escalation","details":"Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2, the asterisk/contrib/scripts/ast_coredumper runs as root, as noted by the NOTES tag on line 689 of the ast_coredumper file. The script will source the contents of /etc/asterisk/ast_debug_tools.conf, which resides in a folder that is writeable by the asterisk user:group. Due to the /etc/asterisk/ast_debug_tools.conf file following bash semantics and it being loaded; an attacker with write permissions may add or modify the file such that when the root ast_coredumper is run; it would source and thereby execute arbitrary bash code found in the /etc/asterisk/ast_debug_tools.conf. This issue has been patched in versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2.","aliases":["GHSA-rvch-3jmx-3jf3"],"modified":"2026-08-12T03:51:15.519269360Z","published":"2026-02-06T16:47:19.611Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/23xxx/CVE-2026-23741.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-427"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/23xxx/CVE-2026-23741.json"},{"type":"ADVISORY","url":"https://github.com/asterisk/asterisk/security/advisories/GHSA-rvch-3jmx-3jf3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-23741"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/asterisk/asterisk","events":[{"introduced":"0"},{"fixed":"d49c5d454f42fc11da7631bea496c66c6473798e"},{"introduced":"12da95e53ff42287ad69d6d5922e06c3d62010ac"},{"fixed":"f0da54060ab01d91d9ddb78d1e5851bb489bbc90"},{"introduced":"8e4a09f71162ebc1e4bb2159dfc638aa2328047c"},{"fixed":"ce9bf76d69f960dcce55f09bec064248e0ec82dc"},{"introduced":"3bb594c9ca712342edeba7d0610af12c08929737"},{"fixed":"65a52c176730f95b3377e8105c189e580e61f926"},{"introduced":"d8a0290d4a8b0ece3955f9c7b895659f8eba88f2"},{"last_affected":"4f31258df77cd9435e014bb526c762a2a036827a"}],"database_specific":{"source":["CPE_RANGE","CPE_STRING"],"cpe":["cpe:2.3:a:sangoma:asterisk:*:*:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:*:*:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:20.7:cert1:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:20.7:cert1-rc1:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:20.7:cert1-rc2:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:20.7:cert2:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:20.7:cert3:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:20.7:cert4:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:20.7:cert5:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:20.7:cert6:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:20.7:cert7:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:20.7:cert8:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0"},{"fixed":"20.18.2"},{"last_affected":"18.9"},{"introduced":"21.0.0"},{"fixed":"21.12.1"},{"introduced":"22.0.0"},{"fixed":"22.8.2"},{"introduced":"23.0.0"},{"fixed":"23.2.2"},{"introduced":"20.7-cert1"},{"last_affected":"20.7-cert1"},{"introduced":"20.7-cert1\\-rc1"},{"last_affected":"20.7-cert1\\-rc1"},{"introduced":"20.7-cert1\\-rc2"},{"last_affected":"20.7-cert1\\-rc2"},{"introduced":"20.7-cert2"},{"last_affected":"20.7-cert2"},{"introduced":"20.7-cert3"},{"last_affected":"20.7-cert3"},{"introduced":"20.7-cert4"},{"last_affected":"20.7-cert4"},{"introduced":"20.7-cert5"},{"last_affected":"20.7-cert5"},{"introduced":"20.7-cert6"},{"last_affected":"20.7-cert6"},{"introduced":"20.7-cert7"},{"last_affected":"20.7-cert7"},{"introduced":"20.7-cert8"},{"last_affected":"20.7-cert8"}]}}],"versions":["20.7-cert1","20.7-cert1\\-rc1","20.7-cert1\\-rc2","20.7-cert2","20.7-cert3","20.7-cert4","20.7-cert5","20.7-cert6","20.7-cert7","20.7-cert8","certified-22.8-cert1-pre1","22.8.2","certified-22.8-cert1","certified-22.8-cert1-rc1","certified-20.7-cert8","23.2.1","22.8.1","21.12.0","20.18.1","23.2.0","22.8.0","20.18.0","20.18.0-rc1","22.8.0-rc1","23.2.0-rc1","23.1.0","22.7.0","20.17.0","certified-20.7-cert7","22.7.0-rc2","21.12.0-rc2","23.1.0-rc2","20.17.0-rc2","23.1.0-rc1","22.7.0-rc1","21.12.0-rc1","20.17.0-rc1","22.6.0","23.0.0","21.11.0","20.16.0","22.6.0-rc2","21.11.0-rc2","20.16.0-rc2","22.6.0-rc1","21.11.0-rc1","20.16.0-rc1","20.15.0","20.15.0-rc3","20.15.0-rc1","20.15.0-rc2","20.15.1","20.15.2","20.14.0","21.10.0","21.10.0-rc3","21.10.0-rc1","21.10.0-rc2","21.10.1","21.10.2","21.9.0","22.5.0","22.5.0-rc3","22.5.0-rc1","22.5.0-rc2","22.5.1","22.5.2","22.4.0","certified-20.7-cert6","certified-20.7-cert5","certified-20.7-cert4","22.4.0-rc1","21.9.0-rc1","20.14.0-rc1","22.3.0","21.8.0","20.13.0","22.3.0-rc1","21.8.0-rc1","20.13.0-rc1","22.2.0","21.7.0","20.12.0","22.2.0-rc2","21.7.0-rc2","20.12.0-rc2","22.2.0-rc1","21.7.0-rc1","20.12.0-rc1","22.1.1","21.6.1","20.11.1","22.1.0","21.6.0","certified-20.7-cert3","20.11.0","22.1.0-rc1","21.6.0-rc1","20.11.0-rc1","22.0.0","21.5.0","20.10.0","20.10.0-rc2","21.5.0-rc2","21.5.0-rc1","20.10.0-rc1","21.4.3","20.9.3","certified-20.7-cert2","21.4.2","20.9.2","21.4.1","20.9.1","certified-20.7-cert1","20.9.0","21.4.0","21.4.0-rc1","20.9.0-rc1","21.3.1","20.8.1","21.3.0","20.8.0","21.3.0-rc1","20.8.0-rc1","certified-20.7-cert1-pre1","20.7.0","21.2.0","21.2.0-rc2","20.7.0-rc2","20.7.0-rc1","21.2.0-rc1","21.1.0","20.6.0","21.1.0-rc2","20.6.0-rc2","21.1.0-rc1","20.6.0-rc1","21.0.2","20.5.2","20.5.1","21.0.1","21.0.0","20.5.0","20.5.0-rc1","20.4.0","20.4.0-rc2","20.4.0-rc1","20.3.1","20.3.0","20.3.0-rc1","20.2.1","20.2.0","20.2.0-rc1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-23741.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:N"}]}