Tag
critical
threat
Hard-Coded JWT Key in Issabel Framework Enabling RCE
2 TTPs 1 CVEA hard-coded HS256 signing key in the Issabel Framework allows unauthenticated attackers to forge JWTs and execute arbitrary commands via the Asterisk manager originate endpoint.
PoC
Issabel Framework +2
remote-code-execution
pbx
cve-2026-89026
2t
1c
updated
high
advisory
FreePBX API and Backup Modules Vulnerabilities Allowing Authenticated RCE and SSH Key Injection
2 TTPsFreePBX has released security advisories to address critical vulnerabilities in its API and Backup modules, affecting FreePBX API (versions prior to 17.0.9) and FreePBX Backup (versions prior to 17.0.11), which include authenticated command injection and arbitrary SSH key injection leading to remote code execution and unauthorized access.
FreePBX API +1
freepbx
vulnerability
command-injection
rce
ssh-key-injection
voip
pbx
linux
2t