CVE-2026-108161: FusionPBX through 5.6.5 OS Command Injection via Caller ID in Recording ZIP Download

Published Oct 10, 2026
·
Updated

FusionPBX through 5.6.5 contains an OS command injection vulnerability in callrecordings::download() that allows unauthenticated attackers to execute commands by placing calls with malicious caller ID values. When the recordname filename template is enabled, attackers can embed shell metacharacters like $(...) in the Caller-ID name or number, executing commands as the web server user once a privileged user downloads multiple recordings as a ZIP.

Affected Software

1 affected component
FusionPBX Fusionpbx<=5.6.5

Event History

Oct 10, 2026
CVE Published
via MITRE·01:55 PM
Data Sourced
via MITRE·01:55 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:16 PM
DescriptionSeverityWeakness
Event
via NVD·03:29 PM

Frequently Asked Questions

1

What conditions are required for exploitation?

The record_name filename template must be enabled. An unauthenticated attacker must be able to place calls with a malicious Caller-ID name or number, and a privileged user must download multiple recordings as a ZIP.

2

Does the attacker need an account or administrative access?

No attacker authentication is required to place the calls carrying the malicious Caller-ID value. However, exploitation is triggered only when a privileged user performs the multiple-recording ZIP download.

3

What permissions would injected commands receive?

Commands execute as the web server user. The provided information does not establish what additional system or application permissions that user has.

4

Are installations affected by default?

The provided information identifies the record_name filename template as an exploitation requirement, but does not state whether that template is enabled by default.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203