Find notable cyber news and cases, enriched with sources, timelines, and signals.

Issabel Framework hard-coded JWT signing key RCE (CVE-2026-89026)

Vulnerability
First reported
Last updated
Happening score
H score 46
1 unique sources, 1 articles

Summary

Hide ▲

CVE-2026-89026 in Issabel Framework is under active exploitation, exposing Asterisk deployments to unauthenticated remote OS command execution through forged bearer tokens. A hard-coded JWT signing key lets attackers mint valid tokens and reach the /pbxapi/manager/originate endpoint. A patch was released on August 1, 2026, and defenders should ensure the latest fix is applied promptly.

Related Happenings

Microsoft Windows passkey relay mitigation for CVE-2026-34348

Advisory/Mitigation
H score31 First: 10.08.2026 15:25 Last: 10.08.2026 15:25 Sources 1

About this happening: Microsoft's CVE-2026-34348 mitigation for Windows Event Logging Service and the reported passkey relay assertions issue reduces exposure to replay-style authentication...

Timeline

  1. 16.09.2026 18:50 2 articles · 2h ago

    Shadowserver Foundation observes CVE-2026-89026 exploitation

    Exploitation Observed

    Shadowserver Foundation first observed exploitation of CVE-2026-89026 on September 9, 2026, indicating active abuse of the Issabel Framework flaw by that date.

    Show sources
  2. 16.09.2026 18:50 1 articles · 2h ago

    Issabel Framework flaw enables forged bearer tokens and remote OS command execution

    Initial Disclosure

    Issabel Framework is under active exploitation for CVE-2026-89026, a critical flaw that lets an unauthenticated remote attacker execute arbitrary OS commands by abusing a hard-coded HS256 JWT signing key in pbxapi index.php. Attackers can forge valid bearer tokens, call the manager /pbxapi/manager/originate endpoint with the System application parameter, and cause Asterisk to execute arbitrary OS commands as the Asterisk user.

    Show sources