CVE Tools

Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution

The Hacker NewsBy The Hacker News

Reported exploitedIssabel PBX

Our summary

Attackers are exploiting CVE-2026-89026 in Issabel Framework, affecting Issabel PBX, to execute operating-system commands remotely without authentication. The flaw uses a JWT signing key shared across installations, allowing forged tokens to invoke Asterisk functionality and run commands as the Asterisk user. A patch released on August 1, 2026 moves the key into "/etc/issabel.conf"; users should apply the latest fixes.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store