logo

Critical Issabel PBX Command Execution Vulnerability Exploited in the Wild

ID: abd5860a-3a50-5409-9e44-4ca93ff55064

STIX ID: report--abd5860a-3a50-5409-9e44-4ca93ff55064

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-09-16

Date Updated: 2026-09-16

Author: Abinaya

...
...

A critical vulnerability (CVE-2026-89026, CVSS v4 9.3) in the Issabel Framework is being actively exploited: a hard-coded HS256 JWT signing key allowed attackers to forge bearer tokens and remotely invoke the pbxapi/manager/originate endpoint to run arbitrary OS commands as the Asterisk user. Organizations should urgently apply the patch (commit b97dbaf0b71c1c36f841e672b664afbeb02773bd), remove the shared signing key, restrict public access to PBX/APIs, review logs for suspicious tokens/originate activity, and treat any signs of compromise as an incident requiring forensic review and rebuilds.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.