CVE-2026-89026 Details
Description
The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS256 JWT signing key in the pbxapi index.php file that is identical across every installation, allowing unauthenticated remote attackers to forge valid bearer tokens. Attackers can use the forged token to call the manager originate endpoint with the System application parameter, causing Asterisk to execute arbitrary OS commands as the Asterisk user. Exploitation evidence was first observed by the Shadowserver Foundation on 2026-09-09.
A vulnerability exists in the Issabel Framework, which supports Issabel PBX software, prior to commit b97dbaf. The issue stems from a hard-coded HS256 JWT signing key in the 'pbxapi' index.php file, identical across all installations. This flaw allows unauthenticated remote attackers to forge valid bearer tokens. The forged tokens can be used to access the manager originate endpoint with the System application parameter, prompting Asterisk to execute arbitrary operating system commands as the Asterisk user.
Users can update to the latest version of the Issabel Framework, which no longer includes the hard-coded JWT key. Instructions for updating can be found in the Issabel documentation.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 15, 2026CISA-ADP
Assessed Sep 17, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-321 | Use of Hard-coded Cryptographic Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Issabel Framework | < b97dbaf0b71c1c36f841e672b664afbeb02773bd |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 17, 2026 | CVE Modified | CISA-ADP |
| Sep 15, 2026 | New CVE Received | [email protected] |
Volerion