logo

Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution

ID: 8a1aadaa-f9c4-5c85-839b-41ef5a5aed00

STIX ID: report--8a1aadaa-f9c4-5c85-839b-41ef5a5aed00

Feed Name: CosmicBytez Labs

Threat Score
90/100

Date Published: 2026-09-16

Date Updated: 2026-09-17

...
...

**Critical Issabel PBX RCE (CVE-2026-89026):** A hardcoded HS256 JWT signing key in Issabel Framework allowed attackers to forge bearer tokens and invoke the pbxapi/manager/originate endpoint to execute arbitrary shell commands as the Asterisk user; the flaw (CVSS v3.1 9.8, v4.0 9.3) was patched by commit b97dbaf0b71c1c36f841e672b664afbeb02773bd on August 1, 2026, but Shadowserver observed exploitation beginning September 9, 2026 — administrators must update, verify /etc/issabel.conf contains a unique signing secret, remove pbxapi from the public internet, audit for originate calls and unusual tokens, and rotate credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.