Junglewise Threat Intelligence

CVE-2026-46514: mwtcmi Frogman plaintext credential disclosure in audit logs

CVE-2026-46514 · Severity: medium · CVSS 6.5 · Published 2026-07-16

Technologies: Mwtcmi Frogman. Vendors: Mwtcmi.

Executive brief

Frogman, a tool for managing PBX (Private Branch Exchange) phone systems, contains a vulnerability where sensitive credentials like passwords and device secrets are stored in plain text within system audit logs. Because the search tool for these logs was accessible to low-privileged users, an attacker with basic access could view these logs to steal administrative passwords or device credentials. This could lead to full unauthorized control over the phone system and its extensions.

Technical details

A vulnerability in Frogman's audit logging mechanism (specifically the auditOutcome function in Frogman.class.php) causes the application to JSON-encode and store full API responses in the 'oc_audit_log' table. Tools such as fm_reset_password and fm_add_extension return plaintext passwords and secrets in their response bodies, which are then persisted to the log. Furthermore, the fm_audit_search tool inherited a default PERM_READ permission level, allowing any authenticated user with low-level privileges to query the logs and extract these credentials. Version 1.6.2 fixes this by implementing a redaction filter for sensitive keys, increasing the required permission level for audit searches to PERM_ADMIN, and providing a script to scrub historical plaintext entries from the database.

Affected products

  • mwtcmi frogman < 1.6.2

Timeline

  • 2026-05-13: disclosed: Disclosed via FreePBX community forum
  • 2026-05-13: patched: Version 1.6.1 released with security fixes; 1.6.2 released shortly after to fix installation regression
  • 2026-07-16: advisory: NVD publication date

References

Related threats