CVE-2026-67609 is a high-severity privilege escalation vulnerability affecting Telenia Software TVox versions 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions. The vulnerability allows attackers with access to the apache account to execute arbitrary commands as root by exploiting an insecure sudoers configuration in /etc/sudoers.d/telenia.
This PatchSiren debrief provides defensive context on CVE-2026-67608, an OS command injection vulnerability in Telenia Software TVox versions 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions. The vulnerability allows authenticated attackers to execute arbitrary operating system commands by passing an unsanitized pid parameter into an exec() call when the action parameter is set to checkProcess.
The Telenia Software TVox authentication bypass vulnerability in set_env.php allows attackers to derive the current page name from PHP_SELF and skip authentication when the value matches 'login_admin.php'. Organizations using Telenia Software TVox, particularly those with exposed instances under the manager HTML directory, should prioritize patching this critical vulnerability to prevent unauthenticated a [truncated]