FusionPBX Caller ID Bug Lets Attackers Run OS Commands
CVE-2026-108161, CVSS 7.5: unauthenticated OS command injection in FusionPBX 5.6.5 and earlier via crafted caller IDs. Update or restrict exposure.

FusionPBX versions through 5.6.5 have a confirmed OS command injection flaw. The attack surface is the phone network itself: an unauthenticated attacker places a call with a crafted caller ID string, the call_recordings::download() function passes it unsanitized to a system call, and commands run on the host. NVD rates this CVE-2026-108161 at CVSS 7.5 (HIGH).
What is affected
FusionPBX is open-source PBX software built on FreeSWITCH, used for enterprise and hosted telephony. All releases through 5.6.5 are vulnerable. The caller ID vector matters because no login or session is needed: the exploit path is a phone call, not the web admin panel.
Deployments exposed to untrusted call traffic are at the most risk. That includes hosted PBX providers, contact centers, and any instance reachable from public SIP trunks.
What to do
Patch first. Update FusionPBX beyond 5.6.5. If your deployment track has no patch ready yet, two interim steps reduce risk:
- Restrict inbound routes to trusted SIP providers only and block inbound calls from arbitrary IP ranges at the firewall.
- Move the FusionPBX admin interface off any internet-facing interface if it is not already behind a VPN or private network.
Monitor call detail records for caller ID values containing shell metacharacters, pipe characters, or backticks. That is the kind of input this class of injection relies on.
The telephony attack vector makes this unusual. Most VoIP operators do not monitor caller ID for injection attempts the way web teams monitor HTTP inputs. That gap is worth closing.
See also: Advantech WISE-6610 Firmware Hit by CVSS 9.9 RCE, Pwn2Own Ireland Closes: $1.26M for 98 Zero-Days
- [ HIGH ]CVE-2026-108161FusionPBX OS command injection via caller ID
Found this useful? Share it.


