Skip to content

Issabel Framework

exploitbulletin.com • September 17, 2026

Hard-coded JWT signing key in Issabel PBX pbxapi allows unauthenticated OS command execution (CVE-2026-89026)

VulnCheck added this to its KEV catalog yesterday citing Shadowserver observations of exploitation beginning 2026-09-09, and any Issabel PBX exposing pbxapi with the old key can be fully compromised by a single forged token.

The Issabel Framework's pbxapi/index.php shipped an HS256 JWT signing key identical on every installation, so any remote attacker can forge a valid bearer token. With that token, the manager originate endpoint can be called with the System application to make Asterisk run arbitrary OS commands as the asterisk user.

Affected: Issabel Framework before commit b97dbaf0b71c1c36f841e672b664afbeb02773bd

Open framework/html/pbxapi/index.php on the PBX: if JWT_KEY is set to the literal string da893kasdfam43k29akdkfaFFlsdfhj23rasdf rather than read from pbxapijwtsecret in /etc/issabel.conf, the system is vulnerable. Check web server logs for requests to the pbxapi manager originate endpoint from unknown sources, review Asterisk logs for originate calls using the System application, and inspect the asterisk user's processes, cron entries and directory for unexpected files.

Update the Issabel Framework to commit b97dbaf0b71c1c36f841e672b664afbeb02773bd or later, then add a pbxapijwtsecret entry to /etc/issabel.conf containing at least 32 random bytes encoded as Base64 (the patched code refuses to start without it). If updating must wait, block external access to the pbxapi path at the firewall or web server.