hacker-news · Crawled Sep 16, 2026
Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution
4 IoCs
Read original article ↗
AI Summary
A critical vulnerability, CVE-2026-89026, in the Issabel Framework is being actively exploited, allowing unauthenticated remote attackers to execute arbitrary operating system commands. The flaw stems from a hard-coded JSON Web Token (JWT) signing key used across all installations, enabling attackers to forge valid bearer tokens. These tokens can be used to call the '/pbxapi/manager/originate' endpoint with the System application parameter, resulting in command execution as the Asterisk user. A patch was released on August 1, 2026, which replaces the hard-coded key with one stored in a configuration file.
AI-extracted · verify before operational use