AI Weekly Malaysia

Back to items Summaries

Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution

ID
25149
Status
summarized
Published
16 Sep 2026, 11:50 PM
Fetched
17 Sep 2026, 12:43 AM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/attackers-exploit-issabel-framework.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
3.5
Created
17 Sep 2026, 12:47 AM
Tags
Audience
developerssaas_founders

What happened

A critical flaw (CVE-2026-89026, CVSS 9.8) in Issabel Framework—an open-source web-based PBX unified communications platform—is under active exploitation. The vulnerability stems from a hard-coded HS256 JWT signing key identical across every installation, allowing unauthenticated remote attackers to forge bearer tokens and execute arbitrary OS commands via Asterisk. A patch was pushed on August 1, 2026, replacing the hard-coded key with one stored in /etc/issabel.conf, and Shadowserver first observed in-the-wild exploitation on September 9, 2026.

Why it matters

If you or your organisation runs Issabel PBX, patch immediately—every installation shares the same hard-coded JWT key, meaning unpatched instances are trivially exploitable for full OS command execution. For the broader audience, this is a cautionary tale about hard-coded secrets in open-source deployments; if you ship self-hosted software, never embed identical signing keys across installations.

Discussion angle

How many self-hosted open-source tools in your stack ship with hard-coded secrets identical across all installs—and would you even know until exploitation starts?

Top