PT-2026-92132 · Unknown · Issabel Framework

CVE-2026-89026

·

Published

2026-09-15

·

Updated

2026-09-27

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Issabel Framework versions prior to commit b97dbaf
Description The Issabel Framework contains a hard-coded HS256 JWT signing key in the pbxapi index.php file that is identical across all installations. This allows unauthenticated remote attackers to forge valid bearer tokens and bypass authentication. Attackers can use these forged tokens to access the /pbxapi/manager/originate endpoint using the System application parameter, which leads to the execution of arbitrary OS commands under the privileges of the Asterisk user. Exploitation evidence was first observed by the Shadowserver Foundation on 2026-09-09.
Recommendations Update the Issabel Framework to the build containing commit b97dbaf and provision a strong, random signing secret in /etc/issabel.conf that is at least 32 bytes after Base64 decoding. Restrict access to the PBX API routes to explicitly approved clients. Disable unused APIs through supported controls. Limit unnecessary outbound network access from the PBX server.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-89026

Affected Products

Issabel Framework