vulnerability
Published 2026-10-10
Verified 2026-10-11

FusionPBX CVE-2026-108161: an outside caller can plant shell commands in a Caller ID name or number that run on the PBX web server when an admin downloads several call recordings as a ZIP; affects 5.6.5 and earlier, fixed in a September git commit

VulnCheck disclosed an OS command injection flaw in FusionPBX, the open-source web management platform for FreeSWITCH phone systems, and the CVE record was published on 10 October 2026. FusionPBX through 5.6.5 is affected. When the record_name filename template is enabled, the call_recordings download function builds a shell command from recording file names that can include the caller's Caller ID name or number, so an unauthenticated attacker who simply places a call with a value such as $(...) in the Caller ID can get commands executed as the web server user later, at the moment a privileged user selects multiple recordings and downloads them as a ZIP. VulnCheck scores it CVSS 4.0 7.7 and CVSS 3.1 7.5 (high attack complexity, user interaction needed) and credits Dilshod Gofurov. The FusionPBX project fixed it in commit 074a693 on 20 September 2026 ('SECURITY - call recording download'), which sanitises the recording name and adds escapeshellarg. No exploitation has been reported. FusionPBX is used by VoIP providers and businesses to host multi-tenant phone systems. Primary: VulnCheck advisory; vendor: FusionPBX fix commit.

Product
FusionPBX (open-source FreeSWITCH PBX web platform) — call recordings module
Versions
5.6.5 and earlier (builds without commit 074a693)
CVSS
(CVSS 4.0); 7.5 (CVSS 3.1) — VulnCheck
Exploited in Australia?
unknown
Patch to
Update FusionPBX to a build that includes commit 074a693 (20 Sep 2026). Until then, turn off the record_name filename template or avoid multi-recording ZIP downloads, and check existing recording file names for shell characters such as $( or backticks.

Primary: VulnCheck — FusionPBX through 5.6.5 OS Command Injection via Caller ID in Recording ZIP Download (CVE-2026-108161) · Vendor: FusionPBX commit 074a693 — SECURITY - call recording download (20 Sep 2026) · CVE: CVE-2026-108161 · CVE-2026-108161 — CVE record (VulnCheck CNA, 10 Oct 2026)

vulnerabilities network