HIGH
fusionpbx
CVE published 2026-10-10
CVE-2026-108161
FusionPBX through 5.6.5 contains an OS command injection vulnerability in call_recordings::download() that allows unauthenticated attackers to execute commands by placing calls with malicious caller ID values. This vulnerability can be exploited by embedding shell metacharacters like $(...) in the Caller-ID name or number, leading to command execution as the web server user when a privileged user download [truncated]