Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution
AI-summarised brief · reviewed before publication
A critical flaw (CVE‑2026‑89026) in Issabel Framework, a web‑based PBX platform, allows unauthenticated attackers to forge a hard‑coded JWT and execute arbitrary OS commands via the /pbxapi/manager/originate endpoint. The vulnerability, rated 9.8 on CVSS v3.1, was first observed on September 9, 2026, after a patch replacing the fixed key with a configurable one was released on August 1, 2026. No confirmed real‑world exploitation details are available, but users are urged to apply the update promptly.
💡 Why It Matters
- · The flaw exposes a widely deployed communications system to remote code execution, potentially compromising critical voice infrastructure across enterprises.
- · Prompt patching is essential to prevent attackers from gaining system-level access.