Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution
Reported exploitedIssabel PBXOur summary
Attackers are exploiting CVE-2026-89026 in Issabel Framework, affecting Issabel PBX, to execute operating-system commands remotely without authentication. The flaw uses a JWT signing key shared across installations, allowing forged tokens to invoke Asterisk functionality and run commands as the Asterisk user. A patch released on August 1, 2026 moves the key into "/etc/issabel.conf"; users should apply the latest fixes.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.