Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 10 Oct 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FusionPBX through 5.6.5 contains an OS command injection vulnerability in call_recordings::download() that allows unauthenticated attackers to execute commands by placing calls with malicious caller ID values. When the record_name filename template is enabled, attackers can embed shell metacharacters like $(...) in the Caller-ID name or number, executing commands as the web server user once a privileged user downloads multiple recordings as a ZIP. | |
| Title | FusionPBX through 5.6.5 OS Command Injection via Caller ID in Recording ZIP Download | |
| First Time appeared |
Fusionpbx
Fusionpbx fusionpbx |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:2.3:a:fusionpbx:fusionpbx:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Fusionpbx
Fusionpbx fusionpbx |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-10T13:55:12.788Z
Reserved: 2026-10-09T15:41:44.132Z
Link: CVE-2026-108161
No data.
Status : Received
Published: 2026-10-10T14:16:37.223
Modified: 2026-10-10T14:16:37.223
Link: CVE-2026-108161
No data.
OpenCVE Enrichment
Updated: 2026-10-10T16:30:18Z