Asterisk XML parser enables XXE and XInclude local file disclosure

Note: This data is for reference and cybersecurity research purposes only.CyStack advises users not to use this information for unlawful purposes.

What is CVE-2026-23739?

CVE-2026-23739 is a vulnerability classified as Improper Restriction of XML External Entity Reference, affecting asterisk (affected versions: < 23.2.2, < 22.8.2, and other affected versions). This vulnerability is rated Medium, with a CVSS score of 6.5. Current sources do not report this vulnerability as exploited.

Overview

Original source data

Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2, the ast_xml_open() function in xml.c parses XML documents using libxml with unsafe parsing options that enable entity expansion and XInclude processing. Specifically, it invokes xmlReadFile() with the XML_PARSE_NOENT flag and later processes XIncludes via xmlXIncludeProcess().If any untrusted or user-supplied XML file is passed to this function, it can allow an attacker to trigger XML External Entity (XXE) or XInclude-based local file disclosure, potentially exposing sensitive files from the host system. This can also be triggered in other cases in which the user is able to supply input in xml format that triggers the asterisk process to parse it. This issue has been patched in versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2.

Affected products and scope

Asterisk is affected on the following release branches:

  • Branch 23: versions <= 23.2.1 are affected; the patched version is 23.2.2.
  • Branch 22: versions <= 22.8.1 are affected; the patched version is 22.8.2.
  • Branch 21: versions <= 21.12.0 are affected; the patched version is 21.12.1.
  • Standard branch 20: versions <= 20.18.1 are affected; the patched version is 20.18.2.
  • Certified branch 20: versions <= 20.7-cert8 are affected; the patched version is 20.7-cert9.

The normalized record expresses these branches using conditions below the corresponding patched release. The status of releases or branches not listed is not established by the available evidence.

Technical details

The ast_xml_open() function in xml.c parses XML documents with libxml using unsafe options. It calls xmlReadFile() with the XML_PARSE_NOENT flag, which enables external entity expansion and loading, and later processes XIncludes through xmlXIncludeProcess(). As a result, attacker-controlled XML can trigger XXE or XInclude processing that reads local files from the host system.

The confirmed precondition is that untrusted or user-supplied XML must reach this function, or another input path must cause the Asterisk process to parse attacker-controlled XML. The specific interface that supplies XML is not established by the available evidence. The weakness is CWE-611, Improper Restriction of XML External Entity Reference.

Exploitability

The record describes a potentially network-reachable attack path, but exploitation still requires attacker-controlled XML to reach the XML parsing flow and requires user interaction. The scoring information in the record is not fully consistent about privilege and complexity requirements, so exposure should not be assumed to be identical across deployments.

The Asterisk advisory states that Asterisk does not currently allow untrusted or user-supplied XML to be used in this way. Actual exploitability therefore depends on a deployment, integration, or future change that allows attacker-controlled XML to reach the parser. The supplied record marks public_exploit as false and does not provide a confirmed exploitation status; this does not prove that exploitation is impossible.

Technical impact

When the relevant input condition exists, Asterisk can resolve external entities or process XIncludes in an XML document, leading to local file reads and disclosure. The technical outcome depends on the Asterisk process's privileges and on whether an attacker can cause the process to parse a document they control.

The established impact is to confidentiality and to the local data accessible to the process. The record does not establish file modification, code execution, or an availability impact. Possible organizational consequences include exposure of configuration or sensitive operational data, but the concrete risk depends on file contents and process permissions.

Business impact

The flaw can disclose data from the host running Asterisk, with the extent determined by the Asterisk process's file permissions and the files within that access scope. If configuration files, credentials, or other operationally sensitive data are readable, disclosure could increase the risk of unauthorized access or support follow-on attacks, although that specific scenario is not established by the evidence.

The directly documented consequence is loss of confidentiality. The available evidence does not establish file modification, code execution, or service disruption. Remediation is more important for systems with integrations that allow users or untrusted network sources to provide XML to Asterisk.

Remediation

  1. Upgrade Asterisk within the deployed release branch to the corresponding patched version: 23.2.2, 22.8.2, 21.12.1, 20.18.2, or 20.7-cert9. Do not infer that a particular fix covers every other release branch.
  2. Recheck inventory after upgrading and confirm that the running process uses the updated binary or package.
  3. Until an upgrade is possible, prevent untrusted XML or user-supplied XML from reaching Asterisk's XML parsing path. This is containment based on the documented precondition, not a vendor-confirmed workaround.
  4. Review new or changed integrations that could pass externally sourced XML into Asterisk. The Asterisk advisory says the current usage does not allow untrusted XML, but that does not remove the risk if the deployment or integration changes.

Detection

  1. Inventory all Asterisk installations and compare each deployment with the affected branches and patched releases listed in affected_summary.
  2. Identify integrations, management tools, or processing paths that can provide untrusted XML files or user-supplied XML data to the Asterisk process.
  3. Where source or binary inspection is available, review use of ast_xml_open(), xmlReadFile() with XML_PARSE_NOENT, and xmlXIncludeProcess(). This is a code and deployment check, not evidence of a specific IOC.
  4. Review file-access telemetry for the Asterisk process for unexpected reads of local files occurring with XML processing activity. This is precautionary monitoring, not a vendor-confirmed indicator.
  5. Do not treat the absence of suspicious log or telemetry events as proof of safety. Confirm both the installed release and the actual XML data path.
Sources (12)
Learn more

Run an in-depth assessment with complete web risk management

CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.

Explore CyStack VulnScan