Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution
- ID
- 25149
- Status
- summarized
- Published
- 16 Sep 2026, 11:50 PM
- Fetched
- 17 Sep 2026, 12:43 AM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/attackers-exploit-issabel-framework.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 3.5
- Created
- 17 Sep 2026, 12:47 AM
- Tags
- Audience
- developerssaas_founders
What happened
A critical flaw (CVE-2026-89026, CVSS 9.8) in Issabel Framework—an open-source web-based PBX unified communications platform—is under active exploitation. The vulnerability stems from a hard-coded HS256 JWT signing key identical across every installation, allowing unauthenticated remote attackers to forge bearer tokens and execute arbitrary OS commands via Asterisk. A patch was pushed on August 1, 2026, replacing the hard-coded key with one stored in /etc/issabel.conf, and Shadowserver first observed in-the-wild exploitation on September 9, 2026.
Why it matters
If you or your organisation runs Issabel PBX, patch immediately—every installation shares the same hard-coded JWT key, meaning unpatched instances are trivially exploitable for full OS command execution. For the broader audience, this is a cautionary tale about hard-coded secrets in open-source deployments; if you ship self-hosted software, never embed identical signing keys across installations.
Discussion angle
How many self-hosted open-source tools in your stack ship with hard-coded secrets identical across all installs—and would you even know until exploitation starts?