CVE-2026-108161 PUBLISHED

FusionPBX through 5.6.5 OS Command Injection via Caller ID in Recording ZIP Download

Assigner: VulnCheck
Reserved: 09.10.2026 Published: 10.10.2026 Updated: 10.10.2026

FusionPBX through 5.6.5 contains an OS command injection vulnerability in call_recordings::download() that allows unauthenticated attackers to execute commands by placing calls with malicious caller ID values. When the record_name filename template is enabled, attackers can embed shell metacharacters like $(...) in the Caller-ID name or number, executing commands as the web server user once a privileged user downloads multiple recordings as a ZIP.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 7.7

Product Status

Vendor fusionpbx
Product fusionpbx
Versions Default: unaffected
  • affected from 0 to 5.6.5 (incl.)

Credits

  • Dilshod Gofurov finder

References

Problem Types

  • Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CWE