CVE-2026-108161: FusionPBX through 5.6.5 OS Command Injection via Caller ID in Recording ZIP Download
FusionPBX through 5.6.5 contains an OS command injection vulnerability in callrecordings::download() that allows unauthenticated attackers to execute commands by placing calls with malicious caller ID values. When the recordname filename template is enabled, attackers can embed shell metacharacters like $(...) in the Caller-ID name or number, executing commands as the web server user once a privileged user downloads multiple recordings as a ZIP.
Affected Software
Event History
Frequently Asked Questions
What conditions are required for exploitation?
The record_name filename template must be enabled. An unauthenticated attacker must be able to place calls with a malicious Caller-ID name or number, and a privileged user must download multiple recordings as a ZIP.
Does the attacker need an account or administrative access?
No attacker authentication is required to place the calls carrying the malicious Caller-ID value. However, exploitation is triggered only when a privileged user performs the multiple-recording ZIP download.
What permissions would injected commands receive?
Commands execute as the web server user. The provided information does not establish what additional system or application permissions that user has.
Are installations affected by default?
The provided information identifies the record_name filename template as an exploitation requirement, but does not state whether that template is enabled by default.