PatchSiren

fusionpbx CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH fusionpbx CVE published 2026-10-10

CVE-2026-108161

FusionPBX through 5.6.5 contains an OS command injection vulnerability in call_recordings::download() that allows unauthenticated attackers to execute commands by placing calls with malicious caller ID values. This vulnerability can be exploited by embedding shell metacharacters like $(...) in the Caller-ID name or number, leading to command execution as the web server user when a privileged user download [truncated]