← back

CVE-2026-89026

CRITICAL · 9.8
hype LIKELY HACK · 78 hack

Active exploitation observed by Shadowserver; high CVSS; no KEV listing yet but early-stage incident reporting dominates signal.

What: Hard-coded HS256 JWT signing key in Issabel Framework (Issabel PBX web framework) allows unauthenticated attackers to forge bearer tokens and execute arbitrary OS commands via Asterisk manager originate endpoint. CVSS 9.8 CRITICAL.

Why it matters: In-the-wild exploitation confirmed by Shadowserver Foundation as of 2026-09-09; affects every Issabel PBX installation identically. No patch commit referenced in public advisories yet, but vulnerability is actively being exploited in production environments.

Where it's seen: Social media chatter on Bluesky amplifying NVD/advisory details same-day as publication; no public PoC code visible yet, but exploitation evidence documented by Shadowserver within 6 days of discovery.

RISK: CRITICAL — Hard-coded key, unauthenticated RCE as Asterisk user, confirmed in-the-wild exploitation by trusted observer.

Generated by claude-haiku-4-5 from public posts and authoritative metadata. AI can make mistakes — verify against vendor advisories before acting. 9/15/2026, 6:33:08 PM

Description

The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS256 JWT signing key in the pbxapi index.php file that is identical across every installation, allowing unauthenticated remote attackers to forge valid bearer tokens. Attackers can use the forged token to call the manager originate endpoint with the System application parameter, causing Asterisk to execute arbitrary OS commands as the Asterisk user. Exploitation evidence was first observed by the Shadowserver Foundation on 2026-09-09.

CVSS 3.1 breakdown

Exploitability 3.9 · Impact 5.9
vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack vector
Network
Complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Weaknesses