← back
CVE-2026-89026criticalobserved exploitationCWE-321

Issabel Framework Hard-coded JWT Key RCE via pbxapi/manager/originate

70Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.

ssvc Actcvss 9.3epss 0.5%
from disclosure to weapon1 days
Published on NVDSep 15
1st PoC+1d
VulnCheckSep 15
exploitation probability
0.5%top 57% of all CVEs
observed exploitation
yesVulnCheck
3 public exploit(s)
The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS256 JWT signing key in the pbxapi index.php file that is identical across every installation, allowing unauthenticated remote attackers to forge valid bearer tokens. Attackers can use the forged token to call the manager originate endpoint with the System application parameter, causing Asterisk to execute arbitrary OS commands as the Asterisk user. Exploitation evidence was first observed by the Shadowserver Foundation on 2026-09-09.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.