Key Facts
VulnCheck reports that CVE-2026-89026 affects Issabel Framework and that exploitation evidence was first observed by Shadowserver on September 9, 2026.
Technical Details
The advisory says the framework used an identical hard-coded HS256 JWT signing key across installations, enabling unauthenticated attackers to forge bearer tokens. It further states that a forged token can invoke a manager endpoint with Asterisk’s System application to execute operating-system commands as the Asterisk user.
Impact & Mitigation
Apply the upstream fix. The Issabel commit replaces the hard-coded key with a secret from /etc/issabel.conf. Review exposed Issabel PBX deployments and investigate suspicious API activity.
