Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-89026— Issabel Framework Hard-coded JWT Key RCE via pbxapi/manager/originate

Quick assessment

Affected
Issabel Foundation Issabel Framework
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 commit b97dbaf 之前的 Issabel Framework(支撑 Issabel PBX 软件的 Web 框架)中,pbxapi 的 index.php 文件中包含一个硬编码的 HS256 JWT 签名密钥。该密钥在所有安装实例中均相同,这使得未认证的远程攻击者能够伪造有效的 Bearer 令牌。攻击者可以利用伪造的令牌调用 manager 的 originate 端点,并传入 System 应用参数,从而让 Asterisk 以 Asterisk 用户身份执行任意操作系统命令。据 Shadows

CVSS 9.8 · Critical

Affected Version Matrix 1

VendorProduct Version RangeStatus
Issabel Foundation Issabel Framework < b97dbaf0b71c1c36f841e672b664afbeb02773bd affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-89026

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Issabel Framework Hard-coded JWT Key RCE via pbxapi/manager/originate
Source: CVE Program / CVE List V5
Vulnerability Description
The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS256 JWT signing key in the pbxapi index.php file that is identical across every installation, allowing unauthenticated remote attackers to forge valid bearer tokens. Attackers can use the forged token to call the manager originate endpoint with the System application parameter, causing Asterisk to execute arbitrary OS commands as the Asterisk user. Exploitation evidence was first observed by the Shadowserver Foundation on 2026-09-09.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
使用硬编码的密码学密钥
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Issabel Foundation Issabel Framework 0 ~ b97dbaf0b71c1c36f841e672b664afbeb02773bd -

II. Public POCs for CVE-2026-89026

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-89026

登录查看更多情报信息。

Patches & Fixes for CVE-2026-89026 (1)

Vendor Advisories for CVE-2026-89026 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-89026

No comments yet


Leave a comment