What is CVE-2026-67608?
This is an OS command injection vulnerability in Telenia Software TVox, affecting authenticated users. The pid parameter in action_audio.php is unsanitized and passed to an exec() call, allowing arbitrary command execution. Versions prior to 26.5.3 in the 26.x branch and prior to 24.9.21 in the 24.x branch are impacted — update to a patched version immediately.
Azərbaycanca: Telenia Software TVox proqramında authenticated istifadəçilərə təsir edən OS command injection zəifliyidir. action_audio.php faylında pid parametri sanitizə olunmadığından, hücumçu exec() çağırışı vasitəsilə sistemdə əmr icra edə bilər. 26.5.3-dən əvvəlki 26.x versiyaları və 24.9.21-dən əvvəlki 24.x versiyaları təsirlənir — dərhal yamaqlanmış versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-78; shared vendor: Telenia Software
FAQ2
Which users are affected by CVE-2026-67608 in Telenia Software TVox?
This OS command injection vulnerability affects authenticated users.
How can I remediate CVE-2026-67608?
You must immediately update Telenia Software TVox to a patched version: version 26.5.3 or later for the 26.x branch, or version 24.9.21 or later for the 24.x branch.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.