CVE-2026-67608
Last modified
CVE-2026-67608 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an OS command injection vulnerability in action_audio.php that allows authenticated attackers to execute arbitrary operating system commands by passing an unsanitized pid parameter into an exec() call when the action parameter is set to checkProcess. Attackers can inject malicious OS commands through the pid request parameter to execute arbitrary commands with the privileges of the apache user.. EPSS estimates a 1.52% chance of exploitation in the next 30 days.
Description
Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an OS command injection vulnerability in action_audio.php that allows authenticated attackers to execute arbitrary operating system commands by passing an unsanitized pid parameter into an exec() call when the action parameter is set to checkProcess. Attackers can inject malicious OS commands through the pid request parameter to execute arbitrary commands with the privileges of the apache user.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Telenia Software | TVox | >= 26.0.0, <= 26.5.3; >= 24.0.0, <= 24.9.21 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-67608?
How severe is CVE-2026-67608?
How do I fix CVE-2026-67608?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-67596CSL 1010 M2M 3G WiFi Module firmware through 2.2.1.4 contain…6.9
- CVE-2026-67598Emlog Pro through 2.6.23 contains a disabled TLS certificate…7.4
- CVE-2026-67599ClearOS 7.9 contains an OS command injection vulnerability i…7.2
- CVE-2026-6760Mitigation bypass in the Networking: Cookies component. This…9.8
- CVE-2026-67602phpIPAM before 1.8.2 contains an authentication bypass vulne…9.1
- CVE-2026-67607LightFTP 2.3.1 contains a residual race condition vulnerabil…5.9
- CVE-2026-67609Telenia Software TVox 26.5.3 and prior 26.x versions, and 24…7.8
- CVE-2026-6761Privilege escalation in the Networking component. This vulne…8.8
- CVE-2026-67610OpenEMR through 8.2.0 contains an improper authentication vu…8.1
- CVE-2026-67611OpenEMR through 8.2.0 contains an authentication bypass vuln…8.1
- CVE-2026-67612OpenEMR through 8.2.0 contains a stored cross-site scripting…4.8
- CVE-2026-67613CyberPanel before 3.0.0 contains a path traversal vulnerabil…4.9
Are you affected by CVE-2026-67608?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
