{"id":2900,"date":"2026-09-16T16:31:08","date_gmt":"2026-09-16T16:31:08","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=2900"},"modified":"2026-09-16T16:31:08","modified_gmt":"2026-09-16T16:31:08","slug":"attackers-exploit-issabel-framework-flaw-enabling-unauthenticated-os-command-execution","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=2900","title":{"rendered":"Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Sep 16, 2026<\/span><\/span><span class=\"p-tags\">Vulnerability \/ Web Security<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh5aXi8Vt3MH8e38-ViNXz-m4hRPrbqDMGcpbMtOc3b-cDLIyEZEjqGvSscW6mR34ZrmPM4lSnv6C9XFTHlgq3UyGLA24gySGqcCzdKr-hIY2QZO8VSXnC-KAsdEz6vTkgdRnVxAZVM7NyrhgpL2xDWR8lcvPInEwgvj0pTgHkC7KStUFglwcLext7eb3w5\/s1700-nu-rw-lo-l85-e365\/issa.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>A critical security flaw in <a href=\"https:\/\/github.com\/IssabelFoundation\/framework\" target=\"_blank\">Issabel Framework<\/a>, a web-based framework for the open-source unified communications PBX software, has come under active exploitation.<\/p>\n<p>The vulnerability in question is <strong><a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-89026\" target=\"_blank\">CVE-2026-89026<\/a><\/strong> (CVSS v3.1 score: 9.8\/CVSS v4.0 score: 9.3), which can allow an unauthenticated remote attacker to execute arbitrary operating system (OS) commands by taking advantage of a hard-coded JSON Web Token (JWT) signing key.<\/p>\n<p>The Issabel Framework \u00abcontains a hard-coded HS256 JWT signing key in the pbxapi index.php file that is identical across every installation, allowing unauthenticated remote attackers to forge valid bearer tokens,\u00bb VulnCheck <a href=\"https:\/\/www.vulncheck.com\/advisories\/issabel-pbx-hard-coded-jwt-key-rce-via-pbxapi-manager-originate\" target=\"_blank\">said<\/a> in an alert.<\/p>\n<p>\u00abAttackers can use the forged token to call the manager <a href=\"https:\/\/github.com\/wwwakcan\/Issabel-PBXAPI-Extension\" target=\"_blank\">&#8216;\/pbxapi\/manager\/originate&#8217; endpoint<\/a> with the System application parameter, causing Asterisk to execute arbitrary OS commands as the Asterisk user.\u00bb<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/enterprise-ai-security-a\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhgJrVTpy3T5kJ7VEIro3XfMOmfqDnBU03fYT5CyFWrs2rE9BeQxs835FAS_f1yivzd7mZ7KartftPk4qs8w5Br-WzfYMXruXDQk4FiuXcvSxoA4XH93ipwJJyy2Hbs9jqs-keS9KZhCnQ2YYdv93M51kxJlE862ob-RrrEhP4DEVP3E79zMMPf43e5keoK\/s728-nu-rw-lo-l85-e365\/AI-eBook-d-2.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>A <a href=\"https:\/\/github.com\/IssabelFoundation\/framework\/commit\/b97dbaf0b71c1c36f841e672b664afbeb02773bd\" target=\"_blank\">patch for the vulnerability<\/a> was pushed on August 1, 2026, and plugs the flaw by replacing the hard-coded JWT key (\u00abda893kasdfam43k29akdkfaFFlsdfhj23rasdf\u00bb) with a JWT key stored in the \u00ab\/etc\/issabel.conf\u00bb file.<\/p>\n<p>According to the cybersecurity company, the Shadowserver Foundation first observed exploitation of CVE-2026-89026 on September 9, 2026. That said, there are currently no details on how the vulnerability is being abused in real-world attacks, who is behind them, and the scale of such efforts.<\/p>\n<p>Users of the Issabel Framework are advised to apply the latest fixes for optimal protection.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Sep 16, 2026Vulnerability \/ Web Security A critical security flaw in Issabel Framework, a web-based framework for the open-source unified communications PBX software, has come under active exploitation. The&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2901,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[622,1223,524,13,120,70,1931,3430,725],"class_list":["post-2900","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-attackers","tag-command","tag-enabling","tag-execution","tag-exploit","tag-flaw","tag-framework","tag-issabel","tag-unauthenticated"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2900","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2900"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2900\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/2901"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2900"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2900"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2900"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}