Issabel Framework Hard-coded JWT Key RCE via pbxapi/manager/originate
70Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.
ssvc Actcvss 9.3epss 0.5%
from disclosure to weapon1 days
Published on NVDSep 15
1st PoC+1d
VulnCheckSep 15
exploitation probability
0.5%top 57% of all CVEs
observed exploitation
yesVulnCheck
3 public exploit(s)
The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS256 JWT signing key in the pbxapi index.php file that is identical across every installation, allowing unauthenticated remote attackers to forge valid bearer tokens. Attackers can use the forged token to call the manager originate endpoint with the System application parameter, causing Asterisk to execute arbitrary OS commands as the Asterisk user. Exploitation evidence was first observed by the Shadowserver Foundation on 2026-09-09.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
Issabel Foundation · Issabel Frameworkpublic PoCs found — 3
githubgithub.com/cflowsec/CVE-2026-89026★ 1githubgithub.com/AranFarzami/CVE-2026-89026★ 1vulncheckvulncheck.com/xdb/9cf54e06e6b8unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.