CVE-2026-108161 | FusionPBX up to 5.6.5 Call Recordings Download download Caller-ID name/Caller-ID number os command injection
A vulnerability labeled as critical has been found in FusionPBX up to 5.6.5. The affected element is the function call_recordings::download of the component Call Recordings Download. The manipulation of the argument Caller-ID name/Caller-ID number results in os command injection.
This vulnerability is reported as CVE-2026-108161. The attack can be launched remotely. No exploit exists.VulDB Recent EntriesRead More