A critical flaw in Issabel Framework, tracked as CVE-2026-89026, is being actively exploited to let unauthenticated attackers execute arbitrary OS commands by forging JWT bearer tokens with a hard-coded signing key. A patch released on August 1, 2026, replaces the shared key, while Shadowserver Foundation first observed exploitation on September 9, 2026. #IssabelFramework #CVE-2026-89026 #ShadowserverFoundation
Keypoints
- CVE-2026-89026 has a critical CVSS score of 9.8.
- The flaw affects Issabel Framework, used for open-source unified communications PBX software.
- Attackers can forge valid JWT bearer tokens because the signing key is hard-coded and shared across installations.
- Exploitation can trigger the Asterisk manager endpoint to run arbitrary OS commands as the Asterisk user.
- A patch was released on August 1, 2026, and users are urged to update immediately.
Read More: https://thehackernews.com/2026/09/attackers-exploit-issabel-framework.html