Skip to content
feed: live
0dayNews
CVE Record
[ HIGH ]CVE-2026-108161

FusionPBX OS command injection via caller ID

FusionPBX through 5.6.5 allows unauthenticated OS command execution via crafted caller IDs processed in the call_recordings::download() function.

Vendor
FusionPBX
Product
FusionPBX (through 5.6.5)
CVSS
7.5
EPSS (exploit probability)
N/A
Status
patched
Published

FusionPBX versions through 5.6.5 contain an OS command injection vulnerability in the call_recordings::download() function. Caller ID data supplied by an unauthenticated caller is passed to a system call without sanitization. An attacker can exploit this by placing a call with a crafted caller ID string containing shell metacharacters.

No authentication is required. The attack vector is the telephony layer, meaning any system accepting inbound calls from untrusted sources is exposed.

Update FusionPBX beyond 5.6.5. If patching is not immediately possible, restrict inbound call routes to trusted SIP trunks and block arbitrary inbound SIP traffic at the network perimeter.

Source: NVD CVE-2026-108161 | FusionPBX on GitHub