What is CVE-2026-89026?
The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS256 JWT signing key in the pbxapi index.php file that is identical across every installation, allowing unauthenticated remote attackers to forge valid bearer tokens. Attackers can use the forged token to call the manager originate endpoint with the System application parameter, causing Asterisk to execute arbitrary OS commands as the Asterisk user. Exploitation evidence was first observed by the Shadowserver Foundation on 2026-09-09.
Timeline
- 2026-09-15Published to the U.S. National Vulnerability Database (NVD)
- 2026-09-17First covered in a defend.network daily briefing
Affected product
See advisory
Remediation Steps
- Identify all systems running Issabel Framework and verify installed version
- Apply the vendor security patch for CVE-2026-89026 immediately
- If patching cannot be applied immediately, restrict network access to Issabel Framework services to trusted administrative networks only
- Monitor system logs for evidence of exploitation (unusual OS command execution from web processes)
- Review recent system activity and file modifications for signs of unauthorized access
References
Referenced in our briefings & reports
Browse all tracked CVEs in the defend.network CVE database →
🤖 This CVE page is generated by defend.network from NVD, CISA KEV, EPSS, and our verified daily briefings. Severity and exploitation data come from official sources; always verify remediation steps against the official vendor advisory before acting in production.