CVE-2026-89026
CVSS 9.8 CRITICAL: the Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded… EPSS 0.5% (43rd percentile).
Vulnerabilities · 4h ago
VulnCheck and Shadowserver say CVE-2026-89026 is under active exploitation in Issabel Framework, where a hard-coded HS256 JSON Web Token (JWT) signing key is identical across installs. The flaw can let an unauthenticated attacker forge a bearer token and reach Asterisk command execution.
The attack works because the framework trusts tokens signed with the same embedded secret everywhere. Once a forged token is accepted, the attacker can call the PBX manager endpoint with a System action and make Asterisk run operating system commands as the Asterisk user.
For operators with Issabel or Asterisk exposed to the network, the exposure is bigger than one host: a single leaked key pattern can scale across deployments without target-specific reconnaissance. The patch changed the signing key location on August 1, but Shadowserver observed exploitation on September 9, so patched or not, any instance that still trusts the shared secret sits in the blast radius.
CVSS 9.8 CRITICAL: the Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded… EPSS 0.5% (43rd percentile).
1 source covering this story
Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution
Issabel Framework flaw CVE-2026-89026 is under active exploitation and can enable unauthenticated OS command execution via a hard-coded JWT key.
Part of the PlainSec briefing for 2026-09-16