โ† Back to Feed

Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution

CVE-2026-89026

September 16, 2026 ยท The Hacker News ยท Severity: CRITICAL

A critical security flaw in Issabel Framework, a web-based framework for the open-source unified communications PBX software, has come under active exploitation. The vulnerability in question is CVE-2026-89026 (CVSS v3.1 score: 9.8/CVSS v4.0 score: 9.3), which can allow an unauthenticated remote attacker to execute arbitrary operating system (OS) commands by taking advantage of a hard-coded JSON Web Token (JWT) signing key that is identical across every installation. ๐Ÿ“Œ **Analyst Note:** CVE-2026-89026 represents a critical risk to PBX infrastructure due to its hard-coded JWT signing key that is identical across all Issabel installations, meaning every unpatched system shares the same authentication bypass vector. The CVSS 9.8 score and active in-the-wild exploitation indicate that threat actors have weaponized this flaw, likely through automated scanning of Internet-exposed Issabel instances. Organizations should treat any Issabel system accessible from untrusted networks as compromised until proven otherwise and prioritize patching, network segmentation, and log review for signs of unauthorized command execution.

A critical security flaw in Issabel Framework , a web-based framework for the open-source unified communications PBX software, has come under active exploitation. The vulnerability in question is CVE-2026-89026 (CVSS v3.1 score: 9.8/CVSS v4.0 score: 9.3), which can allow an unauthenticated remote attacker to execute arbitrary operating system (OS) commands by taking advantage of a hard-coded JSON Web Token (JWT) signing key. The Issabel Framework "contains a hard-coded HS256 JWT signing key in the pbxapi index.php file that is identical across every installation, allowing unauthenticated remote attackers to forge valid bearer tokens," VulnCheck said in an alert. "Attackers can use the forged token to call the manager '/pbxapi/manager/originate' endpoint with the System application parameter, causing Asterisk to execute arbitrary OS commands as the Asterisk user." A patch for the vulnerability was pushed on August 1, 2026, and plugs the flaw by replacing the hard-coded JWT key ("da893kasdfam43k29akdkfaFFlsdfhj23rasdf") with a JWT key stored in the "/etc/issabel.conf" file. According to the cybersecurity company, the Shadowserver Foundation first observed exploitation of CVE-2026-89026 on September 9, 2026. That said, there are currently no details on how the vulnerability is being abused in real-world attacks, who is behind them, and the scale of such efforts. Users of the Issabel Framework are advised to apply the latest fixes for optimal protection. Found this article interesting? Follow us on Google News , Twitter and LinkedIn to read more exclusive content we post.

Key Takeaways

  • Attackers are actively exploiting CVE-2026-89026, a critical Issabel Framework vulnerability with a CVSS 9.8 score allowing unauthenticated remote OS command execution.
  • The flaw stems from a hard-coded HS256 JWT signing key identical across all Issabel installations, enabling attackers to forge authentication tokens trivially.
  • Organizations using Issabel-based PBX systems should update immediately and review access logs for signs of unauthorized command execution associated with this flaw.
โ˜• Buy a Coffee