๐Ÿ” CVE Alert

CVE-2026-108161

HIGH 7.5

FusionPBX through 5.6.5 OS Command Injection via Caller ID in Recording ZIP Download

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

FusionPBX through 5.6.5 contains an OS command injection vulnerability in call_recordings::download() that allows unauthenticated attackers to execute commands by placing calls with malicious caller ID values. When the record_name filename template is enabled, attackers can embed shell metacharacters like $(...) in the Caller-ID name or number, executing commands as the web server user once a privileged user downloads multiple recordings as a ZIP.

CWE CWE-78
Vendor fusionpbx
Product fusionpbx
Published Oct 10, 2026
Stay Ahead of the Next One

Get instant alerts for fusionpbx fusionpbx

Be the first to know when new high vulnerabilities affecting fusionpbx fusionpbx are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

fusionpbx / fusionpbx
0 โ‰ค 5.6.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/fusionpbx/fusionpbx/commit/074a69310100f95171c67db62643cc2aac4f4d37 github.com: https://github.com/fusionpbx/fusionpbx/blob/ac4cd29870e3af67506390800904e262fee7e0ec/app/call_recordings/resources/classes/call_recordings.php#L736-L776 github.com: https://github.com/fusionpbx/fusionpbx vulncheck.com: https://www.vulncheck.com/advisories/fusionpbx-through-5.6.5-os-command-injection-via-caller-id-in-recording-zip-download

Credits

Dilshod Gofurov