CVE-2026-23740 | Asterisk PBX up to 20.7-cert8/20.18.1/21.12.0/22.8.1/23.2.1 /tmp ast_coredumper uncontrolled search path (GHSA-xpc6-x892-v83c / WID-SEC-2026-0327)
A vulnerability identified as problematic has been detected in Asterisk PBX up to 20.7-cert8/20.18.1/21.12.0/22.8.1/23.2.1. The impacted element is the function ast_coredumper of the file /tmp. Performing a manipulation results in uncontrolled search path.
This vulnerability was named CVE-2026-23740. The attack needs to be approached locally. There is no available exploit.
You should upgrade the affected component.