Vulnerability threat dossier

CVE-2026-89026

Issabel FoundationIssabel Framework

The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS256 JWT signing key in the pbxapi index.php file that is identical across every installation, allowing unauthenticated remote attackers to forge valid bearer tokens. Attackers can use the forged token to call the manager originate endpoint with the System application parameter, causing Asterisk to execute arbitrary OS commands as the Asterisk user. Exploitation evidence was first observed by the Shadowserver Foundation on 2026-09-09.

VTP deterministic threat20.6of 100 · CVSS excluded

VTP analyst assessment

Actively exploited Issabel Framework forged-token command execution

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateREVIEWED
AI priorityNONE
AI confidence75%
Public exploitation · VTP factREPORTED

Assessment

CVE-2026-89026 uses a hard-coded JWT signing key shared across Issabel Framework installations. An unauthenticated attacker can forge bearer tokens and invoke a manager endpoint to execute operating-system commands. The Hacker News reports active exploitation.

Why it matters

  • The shared signing key defeats token trust across affected installations.
  • Issabel Framework supports PBX software, so command execution can compromise communications infrastructure.

Evidence

2 record references and 1 source references passed trusted post-response validation. The current deterministic record contains 0 independent evidence groups.

Uncertainties

Active exploitation is reported by one press source; the supplied material does not identify campaign scope.

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

Next watchpoint

If you use Issabel Framework before commit b97dbaf, apply the fix and rotate JWT signing material and any credentials exposed to the affected service.

AI baseline history (3)
  1. BASELINE ASSESSED
    Actively exploited Issabel Framework forged-token command executiongpt-5.6-terra · low
  2. BASELINE ASSESSED
    Issabel Framework forged-token command executiongpt-5.6-terra · low
  3. BASELINE ASSESSED
    Issabel Framework forged-token command executiongpt-5.6-terra · low
Technical severityCRITICALCVSS 9.3 · technical context
Public exploitationREPORTEDGlobal public evidence
Exploit maturityTECHNICAL DETAILSReliability not implied
EPSS0.0143th percentile · prediction
Evidence confidence60%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
01

VTP deterministic assessment

Why this matters

  1. 01

    EPSS is 0.01; this is predictive context, not exploitation evidence.

  2. 02

    First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

02

Material change ledger

What changed

No material changes are recorded for this subject.

03

Claim provenance

Evidence and source independence

2publications detected
2underlying evidence chains

0 primary sources · 0 dependent secondary reports · 2 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

Source claimEXPLOITATION REPORTEDPUBLICATION REPORTS EXPLOITATION
60%claim confidence
UNKNOWNreport:c302c351993cefeb1d93bb79a2e7cd58f7576ff3d2bddb03a8f86d0fadfdf97cACTIVE
Evidence
04

Event history

Threat timeline

  1. 15:5016 Sept
    EXPLOITATION REPORTED

    Exploitation Reported

    The Hacker News supplied a deterministically extracted signal; review the linked evidence before escalation.

05

Original publications

Source record

⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacks

A browser. A plugin. A package. A login screen. Normal stuff. That is basically the problem this week. The trouble keeps showing up inside things people already trust: code that takes a bad turn, old payloads coming back, exposed systems, weak checks, fake fixes, and attack paths that look almost too easy. Even the research side is getting messy, with more findings, more automation, and not

CVE-2025-43936CVE-2026-0310CVE-2026-15315CVE-2026-15316CVE-2026-18851CVE-2026-19666CVE-2026-19667CVE-2026-28302CVE-2026-28304CVE-2026-28305CVE-2026-28306CVE-2026-28307CVE-2026-28308CVE-2026-28309CVE-2026-28310CVE-2026-28311CVE-2026-28312CVE-2026-28313CVE-2026-28314CVE-2026-28315CVE-2026-28316CVE-2026-28317CVE-2026-28321CVE-2026-28323CVE-2026-28326CVE-2026-32882CVE-2026-39919CVE-2026-43502CVE-2026-43790CVE-2026-56711CVE-2026-58138CVE-2026-58704CVE-2026-61410CVE-2026-65346CVE-2026-65400CVE-2026-65414CVE-2026-65638CVE-2026-65812CVE-2026-68121CVE-2026-68488CVE-2026-70416CVE-2026-73178CVE-2026-73324CVE-2026-73693CVE-2026-73694CVE-2026-73698CVE-2026-73699CVE-2026-74469CVE-2026-76163CVE-2026-76460CVE-2026-76669CVE-2026-76670CVE-2026-76672CVE-2026-76673CVE-2026-76674CVE-2026-77147CVE-2026-77179CVE-2026-77692CVE-2026-78175CVE-2026-78623CVE-2026-78626CVE-2026-80172CVE-2026-80238CVE-2026-80274CVE-2026-80844CVE-2026-81000CVE-2026-81642CVE-2026-82079CVE-2026-82232CVE-2026-82717CVE-2026-84607CVE-2026-85061CVE-2026-85982CVE-2026-89026CVE-2026-89049CVE-2026-90894CVE-2026-90999CVE-2026-91721CVE-2026-91726CVE-2026-91749CVE-2026-91843CVE-2026-91931CVE-2026-91932CVE-2026-91998CVE-2026-92005CVE-2026-92013CVE-2026-92015CVE-2026-92020CVE-2026-92022CVE-2026-92029CVE-2026-92033CVE-2026-92034CVE-2026-92038CVE-2026-93372CVE-2026-93374
Separate evidence group
Original

Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution

A critical security flaw in Issabel Framework, a web-based framework for the open-source unified communications PBX software, has come under active exploitation. The vulnerability in question is CVE-2026-89026 (CVSS v3.1 score: 9.8/CVSS v4.0 score: 9.3), which can allow an unauthenticated remote attacker to execute arbitrary operating system (OS) commands by taking advantage of a hard-coded

CVE-2026-89026
Separate evidence group
Original
06

Technical vulnerability data

Context, not threat proof

VTP threat score20.6vtp-threat-v1-public
Public exploitation12 / 30
EPSS prediction0.1 / 20
Exploit availability2.5 / 15
Source independence0 / 15
Intelligence recency6 / 10
Threat acceleration0 / 10
CVSS technical severityExcluded
CVSS
9.3 · CRITICAL
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE
CWE-321
CPE records
0
Deterministic history records
9
Primary technical reference
07

Raw observations

First-party sensor records

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.