TL;DR
The Shadowserver Foundation detected active in-the-wild exploitation of an Issabel PBX vulnerability on September 9, 2026. Attackers are targeting telephony appliances to execute arbitrary operating system commands without authentication. Consequently, administrators must update their communications servers immediately.
- CVE: CVE-2026-89026
- CVSS: 9.8 (Critical · CVSSv3)
- Product: Issabel Foundation Issabel Framework
- Affected: < b97dbaf0b71c1c36f841e672b664afbeb02773bd
- Impact: Issabel Framework Hard-coded JWT Key RCE via pbxapi/manager/originate
- Status: Exploited in the wild
- Patched in: b97dbaf0b71c1c36f841e672b664afbeb02773bd
- Action: Update to b97dbaf0b71c1c36f841e672b664afbeb02773bd now
Track every CVE that hits your stack the moment it's exploited.
Get free email alertsWhy This Threat Matters
Sourced estimates show that thousands of organizations deploy Issabel to manage enterprise phone systems. Therefore, security defects in this platform expose vital communication infrastructure to severe disruption. If an attacker exploits this Issabel PBX vulnerability, they can eavesdrop on telephone calls and steal credentials. Furthermore, intruders can use the compromised host to pivot into private enterprise networks.
How the Attack Works
The vulnerability, designated as CVE-2026-89026, carries a critical CVSS base score of 9.8. The defect resides in the framework API, which relies on a hard-coded HS256 cryptographic key. As researchers observed, this static key remains identical across every installation of the software. Consequently, an unauthenticated attacker can forge valid JSON Web Tokens without knowing any passwords.
The attacker then calls the manager originate endpoint using the System application parameter. This action causes Asterisk to execute arbitrary system commands as the Asterisk user. Security analysts outlined the attack mechanics in a VulnCheck vulnerability advisory.
Affected Versions
This vulnerability affects all Issabel Framework versions prior to commit b97dbaf. Researchers observed confirmed exploitation in the wild starting in September 2026.
Patch and Mitigation Steps
System administrators should apply the update immediately to block unauthorized remote execution. The vendor resolved the issue in the official Issabel Framework patch commit. The fix ensures the system generates unique signing keys for each deployment. Additionally, teams should restrict web management access behind strict network firewalls.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!