## Overview
CVE-2026-89026 is a critical vulnerability in the Issabel Framework, which supports Issabel PBX software. This flaw allows unauthenticated remote attackers to forge valid bearer tokens due to a hard-coded HS256 JWT signing key in the pbxapi index.php file. This key is the same across all installations.
## Technical Details
The vulnerability exists in versions of the Issabel Framework prior to commit b97dbaf. Attackers can exploit this flaw by crafting a forged token. They can then use this token to call the manager originate endpoint with the System application parameter. This action allows them to execute arbitrary operating system commands as the Asterisk user. Evidence of exploitation was first noted by the Shadowserver Foundation on September 9, 2026.
## Impact
Successful exploitation of this vulnerability can lead to severe consequences, including unauthorized access and control over the Asterisk system. Attackers could execute any command with the privileges of the Asterisk user, potentially compromising the entire system and its data.
## Mitigation
Defenders should immediately update the Issabel Framework to the latest version that includes the fix for this vulnerability. Additionally, organizations should review their network security configurations and monitor for any unusual activity related to the Asterisk service. Implementing strict access controls and authentication mechanisms can help mitigate the risk of exploitation.
CSURFACE Threat Sensor