Unauthenticated command execution via shared JWT signing key
Published Sep 15, 2026 · Updated Sep 15, 2026
Hard-coded cryptographic key use in Issabel Foundation Issabel Framework before b97dbaf allows remote attackers to execute OS commands. The pbxapi index.php file assigns the same HS256 JWT signing secret on every installation, so attackers can forge bearer tokens accepted by the API. Unauthenticated network access to pbxapi is sufficient; a forged token can pass the manager originate endpoint an Asterisk System application and run commands as the Asterisk user.
Summary
What happened
Hard-coded cryptographic key use in Issabel Foundation Issabel Framework before b97dbaf allows remote attackers to execute OS commands. The pbxapi index.php file assigns the same HS256 JWT signing secret on every installation, so attackers can forge bearer tokens accepted by the API. Unauthenticated network access to pbxapi is sufficient; a forged token can pass the manager originate endpoint an Asterisk System application and run commands as the Asterisk user.
The record
- CVE
- CVE-2026-89026
- Published
- Sep 15, 2026
- Updated
- Sep 15, 2026
- Vendor
- Issabel Foundation
- Product
- Issabel Framework
- Classifications
- T1059
- Attack vector
- network
- Privileges
- unauthenticated
Timeline
How it unfolded
- Sep 15, 2026CVE publishedPublication date reported by the CVE source.
- Sep 15, 2026Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=0 <b97dbaf0b71c1c36f841e672b664afbeb02773bd
What conditions does exploitation require?
What is affected?
Published CVSS scores
No CVSS assessment is available in this record.
CVSS describes severity. EPSS estimates exploitation probability.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
No public exploit references are available in this record.
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo