PT-2026-92132 · Unknown · Issabel Framework
CVE-2026-89026
·
Published
2026-09-15
·
Updated
2026-09-27
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Issabel Framework versions prior to commit b97dbaf
Description
The Issabel Framework contains a hard-coded HS256 JWT signing key in the
pbxapi index.php file that is identical across all installations. This allows unauthenticated remote attackers to forge valid bearer tokens and bypass authentication. Attackers can use these forged tokens to access the /pbxapi/manager/originate endpoint using the System application parameter, which leads to the execution of arbitrary OS commands under the privileges of the Asterisk user. Exploitation evidence was first observed by the Shadowserver Foundation on 2026-09-09.Recommendations
Update the Issabel Framework to the build containing commit b97dbaf and provision a strong, random signing secret in
/etc/issabel.conf that is at least 32 bytes after Base64 decoding.
Restrict access to the PBX API routes to explicitly approved clients.
Disable unused APIs through supported controls.
Limit unnecessary outbound network access from the PBX server.Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Issabel Framework