
A crucial safety flaw in Issabel Framework, a web-based framework for the open-source unified communications PBX software program, has come underneath lively exploitation.
The vulnerability in query is CVE-2026-89026 (CVSS v3.1 rating: 9.8/CVSS v4.0 rating: 9.3), which may permit an unauthenticated distant attacker to execute arbitrary working system (OS) instructions by making the most of a hard-coded JSON Net Token (JWT) signing key.
The Issabel Framework “comprises a hard-coded HS256 JWT signing key within the pbxapi index.php file that’s an identical throughout each set up, permitting unauthenticated distant attackers to forge legitimate bearer tokens,” VulnCheck mentioned in an alert.
“Attackers can use the solid token to name the supervisor ‘/pbxapi/supervisor/originate’ endpoint with the System utility parameter, inflicting Asterisk to execute arbitrary OS instructions because the Asterisk person.”
A patch for the vulnerability was pushed on August 1, 2026, and plugs the flaw by changing the hard-coded JWT key (“da893kasdfam43k29akdkfaFFlsdfhj23rasdf”) with a JWT key saved within the “/and many others/issabel.conf” file.
Based on the cybersecurity firm, the Shadowserver Basis first noticed exploitation of CVE-2026-89026 on September 9, 2026. That mentioned, there are presently no particulars on how the vulnerability is being abused in real-world assaults, who’s behind them, and the size of such efforts.
Customers of the Issabel Framework are suggested to use the newest fixes for optimum safety.

