VMTech
Discuss a project

Actively Exploited Issabel Flaw Enables Unauthenticated Commands

Actively Exploited Issabel Flaw Enables Unauthenticated Commands

Issabel vulnerability is under active exploitation

A critical vulnerability in the Issabel Framework is being actively exploited, creating a path for unauthenticated remote attackers to execute arbitrary operating-system commands. The flaw, tracked as CVE-2026-89026, has a CVSS v3.1 score of 9.8 and a CVSS v4.0 score of 9.3.

Issabel Framework is the web-based framework used with the open-source unified communications PBX software. The defect affects JWT authentication in its PBX API and can ultimately cause commands to run under the Asterisk user account.

Shadowserver Foundation first observed exploitation on September 9, 2026. The available reporting does not identify the actors responsible, their methods in real-world intrusions, or the scale of the activity.

A shared JWT key enables token forgery

VulnCheck said the vulnerable pbxapi/index.php file contains a hard-coded HS256 JSON Web Token signing key that is identical across every installation. Because the key is shared, an unauthenticated attacker can create bearer tokens that the affected application accepts as valid.

Those forged tokens can be used to call the manager endpoint /pbxapi/manager/originate. By supplying the System application parameter, an attacker can cause Asterisk to execute arbitrary OS commands as the Asterisk user.

The vulnerability is notable because the attacker does not need legitimate credentials before reaching the command-execution step. The combination of remote access, no authentication requirement and a high severity score makes internet-facing deployments especially important to address.

Patch status and operational response

A patch was released on August 1, 2026. It replaces the embedded JWT key, da893kasdfam43k29akdkfaFFlsdfhj23rasdf, with a JWT key stored in /etc/issabel.conf.

Organizations using Issabel Framework should apply the latest available fixes without delay. They should also identify exposed deployments and review affected PBX environments for unexpected activity involving bearer tokens, the manager originate endpoint, or commands executed by the Asterisk user. Prompt patching and targeted review are the practical priority while details of the observed attacks remain limited.

#cybersecurity#vulnerability#pbxsecurity#issabel
Open analytics
On the site 0 views
min read 2 16.09.2026
Instagram

Actively Exploited Issabel Flaw Enables Unauthenticated Commands

Open the post on Instagram ↗