Download Privacy Needle App

Type to search

Cybersecurity

Attackers Exploiting Critical Issabel Framework Flaw for Remote Command Execution

Share

Attackers are actively exploiting a critical security flaw in the Issabel Framework, an open-source unified communications PBX software, to execute operating system (OS) commands without authentication.

The vulnerability, tracked as CVE-2026-89026, carries a CVSS v3.1 score of 9.8 and a CVSS v4.0 score of 9.3. The flaw enables unauthenticated remote attackers to forge valid bearer tokens by taking advantage of a hard-coded HS256 JSON Web Token (JWT) signing key.

Security researchers at VulnCheck identified that the framework contains a hard-coded JWT signing key within the pbxapi/index.php file that is identical across every installation. This allows attackers to forge tokens and call the /pbxapi/manager/originate endpoint using the System application parameter, which causes the Asterisk service to execute arbitrary OS commands with the privileges of the Asterisk user.

The Shadowserver Foundation first observed the active exploitation of CVE-2026-89026 on 9 September 2026. While exploitation has been confirmed, there is currently no detailed information regarding the identity of the threat actors or the full scale of the attacks.

Patch and Remediation

A patch for the vulnerability was released on 1 August 2026. The update mitigates the risk by replacing the hard-coded JWT key with a unique key stored in the /etc/issabel.conf file.

Organisations using the Issabel Framework are urged to apply the latest security updates immediately to prevent unauthorised remote command execution.

Watch Our Latest Video
Stay ahead with expert insights on privacy, cybersecurity, artificial intelligence, data protection and compliance.
No Leak, No Wahala
Published: August 16, 2026
Daily Privacy News
Cybersecurity Updates
Data Protection Tips
GDPR & NDPA Explained
Tags:
Ikeh James Certified Data Protection Officer (CDPO) | NDPC-Accredited

Ikeh James Ifeanyichukwu is a Certified Data Protection Officer (CDPO) accredited by the Institute of Information Management (IIM) in collaboration with the Nigeria Data Protection Commission (NDPC). With years of experience supporting organizations in data protection compliance, privacy risk management, and NDPA implementation, he is committed to advancing responsible data governance and building digital trust in Africa and beyond. In addition to his privacy and compliance expertise, James is a Certified IT Expert, Data Analyst, and Web Developer, with proven skills in programming, digital marketing, and cybersecurity awareness. He has a background in Statistics (Yabatech) and has earned multiple certifications in Python, PHP, SEO, Digital Marketing, and Information Security from recognized local and international institutions. James has been recognized for his contributions to technology and data protection, including the Best Employee Award at DKIPPI (2021) and the Outstanding Student Award at GIZ/LSETF Skills & Mentorship Training (2019). At Privacy Needle, he leverages his diverse expertise to break down complex data privacy and cybersecurity issues into clear, actionable insights for businesses, professionals, and individuals navigating today’s digital world.

  • 1

Leave a Reply

Your email address will not be published. Required fields are marked *

  • Rating

This site uses Akismet to reduce spam. Learn how your comment data is processed.