CVE-2026-67608 HIGH

CVE-2026-67608: Telenia TVox 26.5.3 OS Command Injection via action_audio.php

Vendor Telenia Software
Product TVox
Weakness CWE-78
Published August 3, 2026
Last update August 3, 2026

CVSS base score

8.6/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an OS command injection vulnerability in action_audio.php that allows authenticated attackers to execute arbitrary operating system commands by passing an unsanitized pid parameter into an exec() call when the action parameter is set to checkProcess. Attackers can inject malicious OS commands through the pid request parameter to execute arbitrary commands with the privileges of the apache user.

Key dates

02Disclosure timeline

August 3, 2026 CVE published
August 3, 2026 Record updated

Related vulnerabilities

04Related CVE