CVE-2026-108161
Received Received - Intake

OS Command Injection in FusionPBX

Vulnerability report for CVE-2026-108161, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: VulnCheck

Description

FusionPBX through 5.6.5 contains an OS command injection vulnerability in call_recordings::download() that allows unauthenticated attackers to execute commands by placing calls with malicious caller ID values. When the record_name filename template is enabled, attackers can embed shell metacharacters like $(...) in the Caller-ID name or number, executing commands as the web server user once a privileged user downloads multiple recordings as a ZIP.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-10
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
fusionpbx fusionpbx 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-78 The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

FusionPBX through 5.6.5 has an OS command injection vulnerability in the call_recordings::download() function. Unauthenticated attackers can execute commands by placing calls with malicious caller ID values containing shell metacharacters like $(...). When a privileged user downloads multiple recordings as a ZIP file with the record_name filename template enabled, the system executes the injected commands as the web server user.

Detection Guidance

Check FusionPBX versions with `fusionpbx-version` or inspect `/var/www/fusionpbx/resources/version.php` for versions <= 5.6.5. Monitor system logs for unusual ZIP download commands or shell metacharacters in Caller ID fields during recording downloads.

Impact Analysis

This vulnerability allows attackers to execute arbitrary commands on the server running FusionPBX. This could lead to full system compromise, unauthorized access to sensitive data, installation of malware, or disruption of PBX services. Attackers could steal call recordings, eavesdrop on calls, or pivot to other systems in the network.

Compliance Impact

This vulnerability could severely impact compliance with GDPR and HIPAA by enabling unauthorized access to sensitive call recordings and personal data. GDPR requires protection of personal data, while HIPAA mandates secure handling of protected health information. A breach could result in legal penalties, fines, and reputational damage for organizations using vulnerable versions of FusionPBX.

Mitigation Strategies

Upgrade FusionPBX to the latest version beyond 5.6.5. Disable the record_name filename template if enabled. Review and apply the input sanitization changes in call_recordings.php, particularly in the download method, to block shell metacharacters and enforce safe filename patterns.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108161. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart