Key Facts

VulnCheck reports that CVE-2026-89026 affects Issabel Framework and that exploitation evidence was first observed by Shadowserver on September 9, 2026.

Technical Details

The advisory says the framework used an identical hard-coded HS256 JWT signing key across installations, enabling unauthenticated attackers to forge bearer tokens. It further states that a forged token can invoke a manager endpoint with Asterisk’s System application to execute operating-system commands as the Asterisk user.

Impact & Mitigation

Apply the upstream fix. The Issabel commit replaces the hard-coded key with a secret from /etc/issabel.conf. Review exposed Issabel PBX deployments and investigate suspicious API activity.

Sources

By Allan