Issabel Framework hard-coded JWT signing key RCE (CVE-2026-89026)
Vulnerability
Summary
Hide ▲
Show ▼
CVE-2026-89026 in Issabel Framework is under active exploitation, exposing Asterisk deployments to unauthenticated remote OS command execution through forged bearer tokens. A hard-coded JWT signing key lets attackers mint valid tokens and reach the /pbxapi/manager/originate endpoint. A patch was released on August 1, 2026, and defenders should ensure the latest fix is applied promptly.
Related Happenings
Microsoft Windows passkey relay mitigation for CVE-2026-34348
Advisory/Mitigation
H score31
First: 10.08.2026 15:25
Last: 10.08.2026 15:25
Sources 1
About this happening:
Microsoft's CVE-2026-34348 mitigation for Windows Event Logging Service and the reported passkey relay assertions issue reduces exposure to replay-style authentication...
Microsoft Windows passkey relay mitigation for CVE-2026-34348
Advisory/MitigationAbout this happening: Microsoft's CVE-2026-34348 mitigation for Windows Event Logging Service and the reported passkey relay assertions issue reduces exposure to replay-style authentication...
Timeline
-
16.09.2026 18:50 1 articles · 2h ago
Issabel Framework patch replaces hard-coded JWT signing key
Mitigation Patch UpdateA patch for CVE-2026-89026 was pushed on August 1, 2026, replacing the hard-coded JWT key in Issabel Framework's pbxapi index.php with a JWT key stored in /etc/issabel.conf.
Show sources
- Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution — thehackernews.com — 16.09.2026 18:50
-
16.09.2026 18:50 2 articles · 2h ago
Shadowserver Foundation observes CVE-2026-89026 exploitation
Exploitation ObservedShadowserver Foundation first observed exploitation of CVE-2026-89026 on September 9, 2026, indicating active abuse of the Issabel Framework flaw by that date.
Show sources
- Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution — thehackernews.com — 16.09.2026 18:50
- Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution — thehackernews.com — 16.09.2026 18:50
-
16.09.2026 18:50 1 articles · 2h ago
Issabel Framework flaw enables forged bearer tokens and remote OS command execution
Initial DisclosureIssabel Framework is under active exploitation for CVE-2026-89026, a critical flaw that lets an unauthenticated remote attacker execute arbitrary OS commands by abusing a hard-coded HS256 JWT signing key in pbxapi index.php. Attackers can forge valid bearer tokens, call the manager /pbxapi/manager/originate endpoint with the System application parameter, and cause Asterisk to execute arbitrary OS commands as the Asterisk user.
Show sources
- Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution — thehackernews.com — 16.09.2026 18:50