Remote Code Execution Vulnerability in Issabel PBX Software
CVE-2026-89026

9.3CRITICAL

Key Information:

Vendor
CVE Published:
15 September 2026

What is CVE-2026-89026?

The Issabel Framework, utilized by Issabel PBX software, has a serious vulnerability due to a hard-coded HS256 JWT signing key in the pbxapi index.php file. This identical key across all installations allows unauthorized remote attackers to create valid bearer tokens. By exploiting this flaw, attackers can invoke the manager originate endpoint with the System application parameter, thereby compelling Asterisk to execute arbitrary operating system commands as the Asterisk user. Initial evidence of exploitation was detected by the Shadowserver Foundation on September 9, 2026.

Affected Version(s)

Issabel Framework 0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

The Shadowserver Foundation
.