CVE-2026-46514: Mwtcmi Frogman
Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.
Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.2, fm_reset_password in Tools/ResetPassword.php:48-53 returned a plaintext password and fm_add_extension in Tools/AddExtension.php:172 returned a plaintext secret; Frogman.class.php:2207-2211 used auditOutcome to JSON-encode those responses into oc_audit_log.detail, allowing any PERM_READ caller with access to fm_audit_search to recover the stored credentials. This issue is fixed in version 1.6.2.
Affected products
- Mwtcmi Frogman: before 1.6.2 (fixed in 1.6.2)
Published 2026-07-16. Last modified 2026-07-17.