U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2026-23740

Change History

Initial Analysis by NIST 2/10/2026 1:25:39 PM

Action Type Old Value New Value
Added CVSS V3.1

								
							
							
						
AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Added CPE Configuration

								
							
							
						
OR
          *cpe:2.3:a:sangoma:asterisk:*:*:*:*:*:*:*:* versions up to (excluding) 20.18.2
          *cpe:2.3:a:sangoma:asterisk:*:*:*:*:*:*:*:* versions from (including) 21.0.0 up to (excluding) 21.12.1
          *cpe:2.3:a:sangoma:asterisk:*:*:*:*:*:*:*:* versions from (including) 22.0.0 up to (excluding) 22.8.2
          *cpe:2.3:a:sangoma:asterisk:*:*:*:*:*:*:*:* versions from (including) 23.0.0 up to (excluding) 23.2.2
Added CPE Configuration

								
							
							
						
OR
          *cpe:2.3:a:sangoma:certified_asterisk:18.9:cert2:*:*:*:*:*:*
          *cpe:2.3:a:sangoma:certified_asterisk:18.9:cert1:*:*:*:*:*:*
          *cpe:2.3:a:sangoma:certified_asterisk:18.9:cert3:*:*:*:*:*:*
          *cpe:2.3:a:sangoma:certified_asterisk:18.9:cert4:*:*:*:*:*:*
          *cpe:2.3:a:sangoma:certified_asterisk:18.9:cert5:*:*:*:*:*:*
          *cpe:2.3:a:sangoma:certified_asterisk:13.13.0:cert1:*:*:*:*:*:*
          *cpe:2.3:a:sangoma:certified_asterisk:13.13.0:cert1-rc1:*:*:*:*:*:*
          *cpe:2.3:a:sangoma:certified_asterisk:13.13.0:cert1-rc2:*:*:*:*:*:*
          *cpe:2.3:a:sangoma:certified_asterisk:13.13.0:cert1-rc3:*:*:*:*:*:*
          *cpe:2.3:a:sangoma:certified_asterisk:13.13.0:cert1-rc4:*:*:*:*:*:*
          *cpe:2.3:a:sangoma:certified_asterisk:13.13.0:cert2:*:*:*:*:*:*
          *cpe:2.3:a:sangoma:certified_asterisk:13.13.0:cert3:*:*:*:*:*:*
          *cpe:2.3:a:sangoma:certified_asterisk:13.13.0:rc1:*:*:*:*:*:*
          *cpe:2.3:a:sangoma:certified_asterisk:13.13.0:rc2:*:*:*:*:*:*
          *cpe:2.3:a:sangoma:certified_asterisk:16.8.0:-:*:*:*:*:*:*
          *cpe:2.3:a:sangoma:certified_asterisk:16.8.0:cert1:*:*:*:*:*:*
          *cpe:2.3:a:sangoma:certified_asterisk:16.8.0:cert10:*:*:*:*:*:*
          *cpe:2.3:a:sangoma:certified_asterisk:16.8.0:cert11:*:*:*:*:*:*
          *cpe:2.3:a:sangoma:certified_asterisk:16.8.0:cert12:*:*:*:*:*:*
          *cpe:2.3:a:sangoma:certified_asterisk:16.8.0:cert2:*:*:*:*:*:*
          *cpe:2.3:a:sangoma:certified_asterisk:16.8.0:cert3:*:*:*:*:*:*
          *cpe:2.3:a:sangoma:certified_asterisk:16.8.0:cert4:*:*:*:*:*:*
          *cpe:2.3:a:sangoma:certified_asterisk:16.8.0:cert5:*:*:*:*:*:*
          *cpe:2.3:a:sangoma:certified_asterisk:16.8.0:cert6:*:*:*:*:*:*
          *cpe:2.3:a:sangoma:certified_asterisk:16.8.0:cert7:*:*:*:*:*:*
          *cpe:2.3:a:sangoma:certified_asterisk:16.8.0:cert8:*:*:*:*:*:*
          *cpe:2.3:a:sangoma:certified_asterisk:16.8.0:cert9:*:*:*:*:*:*
          *cpe:2.3:a:sangoma:certified_asterisk:18.9:cert1-rc1:*:*:*:*:*:*
          *cpe:2.3:a:sangoma:certified_asterisk:18.9:-:*:*:*:*:*:*
          *cpe:2.3:a:sangoma:certified_asterisk:18.9:cert10:*:*:*:*:*:*
          *cpe:2.3:a:sangoma:certified_asterisk:18.9:cert11:*:*:*:*:*:*
          *cpe:2.3:a:sangoma:certified_asterisk:18.9:cert12:*:*:*:*:*:*
          *cpe:2.3:a:sangoma:certified_asterisk:18.9:cert13:*:*:*:*:*:*
          *cpe:2.3:a:sangoma:certified_asterisk:18.9:cert6:*:*:*:*:*:*
          *cpe:2.3:a:sangoma:certified_asterisk:18.9:cert7:*:*:*:*:*:*
          *cpe:2.3:a:sangoma:certified_asterisk:18.9:cert8:*:*:*:*:*:*
          *cpe:2.3:a:sangoma:certified_asterisk:18.9:cert8-rc1:*:*:*:*:*:*
          *cpe:2.3:a:sangoma:certified_asterisk:18.9:cert8-rc2:*:*:*:*:*:*
          *cpe:2.3:a:sangoma:certified_asterisk:18.9:cert9:*:*:*:*:*:*
          *cpe:2.3:a:sangoma:certified_asterisk:20.7:cert1:*:*:*:*:*:*
          *cpe:2.3:a:sangoma:certified_asterisk:20.7:cert1-rc1:*:*:*:*:*:*
          *cpe:2.3:a:sangoma:certified_asterisk:20.7:cert1-rc2:*:*:*:*:*:*
          *cpe:2.3:a:sangoma:certified_asterisk:20.7:cert2:*:*:*:*:*:*
          *cpe:2.3:a:sangoma:certified_asterisk:20.7:cert3:*:*:*:*:*:*
          *cpe:2.3:a:sangoma:certified_asterisk:20.7:cert4:*:*:*:*:*:*
          *cpe:2.3:a:sangoma:certified_asterisk:20.7:cert5:*:*:*:*:*:*
          *cpe:2.3:a:sangoma:certified_asterisk:20.7:cert6:*:*:*:*:*:*
          *cpe:2.3:a:sangoma:certified_asterisk:18.9:cert14:*:*:*:*:*:*
          *cpe:2.3:a:sangoma:certified_asterisk:18.9:cert15:*:*:*:*:*:*
          *cpe:2.3:a:sangoma:certified_asterisk:18.9:cert16:*:*:*:*:*:*
          *cpe:2.3:a:sangoma:certified_asterisk:16.8:cert1-rc1:*:*:*:*:*:*
          *cpe:2.3:a:sangoma:certified_asterisk:16.8:cert1-rc2:*:*:*:*:*:*
          *cpe:2.3:a:sangoma:certified_asterisk:16.8:cert1-rc3:*:*:*:*:*:*
          *cpe:2.3:a:sangoma:certified_asterisk:16.8:cert1-rc4:*:*:*:*:*:*
          *cpe:2.3:a:sangoma:certified_asterisk:16.8:cert1-rc5:*:*:*:*:*:*
          *cpe:2.3:a:sangoma:certified_asterisk:16.8:cert10:*:*:*:*:*:*
          *cpe:2.3:a:sangoma:certified_asterisk:16.8:cert11:*:*:*:*:*:*
          *cpe:2.3:a:sangoma:certified_asterisk:16.8:cert12:*:*:*:*:*:*
          *cpe:2.3:a:sangoma:certified_asterisk:16.8:cert13:*:*:*:*:*:*
          *cpe:2.3:a:sangoma:certified_asterisk:16.8:cert14:*:*:*:*:*:*
          *cpe:2.3:a:sangoma:certified_asterisk:16.8:cert4-rc1:*:*:*:*:*:*
          *cpe:2.3:a:sangoma:certified_asterisk:16.8:cert4-rc2:*:*:*:*:*:*
          *cpe:2.3:a:sangoma:certified_asterisk:16.8:cert4-rc3:*:*:*:*:*:*
          *cpe:2.3:a:sangoma:certified_asterisk:16.8:cert4-rc4:*:*:*:*:*:*
          *cpe:2.3:a:sangoma:certified_asterisk:20.7:cert7:*:*:*:*:*:*
          *cpe:2.3:a:sangoma:certified_asterisk:13.13.0:-:*:*:*:*:*:*
Added Reference Type

								
							
							
						
GitHub, Inc.: https://github.com/asterisk/asterisk/security/advisories/GHSA-xpc6-x892-v83c Types: Vendor Advisory