Remote Code Execution Vulnerability in Issabel PBX Software
CVE-2026-89026
9.3CRITICAL
What is CVE-2026-89026?
The Issabel Framework, utilized by Issabel PBX software, has a serious vulnerability due to a hard-coded HS256 JWT signing key in the pbxapi index.php file. This identical key across all installations allows unauthorized remote attackers to create valid bearer tokens. By exploiting this flaw, attackers can invoke the manager originate endpoint with the System application parameter, thereby compelling Asterisk to execute arbitrary operating system commands as the Asterisk user. Initial evidence of exploitation was detected by the Shadowserver Foundation on September 9, 2026.
Affected Version(s)
Issabel Framework 0
