{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-89026/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-89026"}],"_cs_exploited":false,"_cs_has_poc":true,"_cs_poc_references":["https://sploitus.com/exploit?id=C45DA87D-ABC5-5D6C-88FA-49A45DFF6A53\u0026utm_source=rss\u0026utm_medium=rss"],"_cs_products":["Issabel Framework (\u003c commit b97dbaf)","Issabel PBX","Issabel Framework"],"_cs_severities":["critical"],"_cs_tags":["remote-code-execution","pbx","cve-2026-89026"],"_cs_type":"threat","_cs_vendors":["Issabel"],"content_html":"\u003cp\u003eThe Issabel Framework, which serves as the web management interface for Issabel PBX software, contains a critical security vulnerability (CVE-2026-89026) due to a hard-coded HS256 JWT signing key present in the 'pbxapi/index.php' file. This key is identical across all Issabel PBX installations, enabling unauthenticated remote attackers to generate valid bearer tokens. By utilizing these forged tokens, an attacker can authenticate to the 'manager originate' endpoint. This endpoint, intended for administrative control of the telephony system, accepts an 'Application' parameter that supports the 'System' command. Attackers can leverage this to execute arbitrary OS commands on the host system running with the privileges of the Asterisk user. The Shadowserver Foundation first observed exploitation of this vulnerability in the wild on September 9, 2026. This issue affects versions of the Issabel Framework prior to commit b97dbaf.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs reconnaissance to identify internet-facing Issabel PBX instances.\u003c/li\u003e\n\u003cli\u003eAttacker retrieves the hard-coded HS256 signing key from publicly available repository commits.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious JWT using the compromised secret and signs it to impersonate a privileged administrator.\u003c/li\u003e\n\u003cli\u003eAttacker sends an HTTP request to the '/pbxapi/index.php' endpoint or related API routes with the forged Bearer token in the Authorization header.\u003c/li\u003e\n\u003cli\u003eAttacker makes a request to the 'manager originate' API endpoint, injecting the 'System' application string with a malicious OS command into the request body.\u003c/li\u003e\n\u003cli\u003eThe Asterisk service receives the command and interprets the 'System' parameter, spawning a shell process.\u003c/li\u003e\n\u003cli\u003eArbitrary code executes on the underlying operating system with the permissions of the Asterisk user.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation grants unauthenticated attackers full remote code execution on Issabel PBX appliances. This allows for total system compromise, including the ability to exfiltrate call records, intercept communications, or pivot into the internal network. Exploitation has been observed in the wild by the Shadowserver Foundation, indicating wide-scale scanning and targeting of vulnerable PBX infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately update Issabel Framework to commit b97dbaf or later to remove the hard-coded secret and implement unique per-installation key management.\u003c/li\u003e\n\u003cli\u003eRestrict access to the Issabel PBX management web interface and API endpoints (pbxapi) to trusted management subnets using firewall rules.\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs for anomalous POST requests to 'pbxapi/index.php' followed by 'manager originate' parameters.\u003c/li\u003e\n\u003cli\u003eReview all scheduled jobs and user accounts on Issabel PBX servers for signs of persistence established by the Asterisk user.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-16T18:56:38Z","date_published":"2026-09-15T17:42:18Z","id":"https://feed.craftedsignal.io/briefs/2026-09-issabel-rce/","summary":"A hard-coded HS256 signing key in the Issabel Framework allows unauthenticated attackers to forge JWTs and execute arbitrary commands via the Asterisk manager originate endpoint.","title":"Hard-Coded JWT Key in Issabel Framework Enabling RCE","url":"https://feed.craftedsignal.io/briefs/2026-09-issabel-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-89026","version":"https://jsonfeed.org/version/1.1"}