#VU122442 Insecure library loading in Asterisk Open Source and Certified Asterisk - CVE-2026-23740
Published: February 6, 2026
Asterisk Open Source
Certified Asterisk
Digium (Linux Support Services)
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to the application loads dynamic libraries in an insecure manner from the /tmp directory. A local user can place a specially crafted library file into the /tmp directory and execute arbitrary code on the system with root privileges.