CRITICAL 9.8 CVE-2026-89026 Published 15 Sept 2026

Issabel PBX Web Framework JWT Signing Key Exposure

Worried this affects one of your servers?

The Issabel Framework, supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS256 JWT signing key in the pbxapi index.php file, identical across installations.

This allows unauthenticated attackers to forge valid bearer tokens, enabling them to call the manager originate endpoint with the System application parameter, causing Asterisk to execute arbitrary OS commands as the Asterisk user.

Exploitation evidence was first observed on 2026-09-09.

Reference: CVE-2026-89026 on NVD

← Back to Security News