Issabel Framework ships hardcoded JWT key in pbxapi (CVE-2026-89026)
The open-source Issabel Framework, built on Asterisk, shipped a single hardcoded HS256 signing key in its pbxapi component. Tracked as CVE-2026-89026 with a CVSS score of 9.8, the flaw lets attackers forge a bearer token and execute code on the Asterisk host; it was fixed in commit b97dbaf, with first exploitation evidence reported on 9 September 2026.
- CVE-2026-89026: CVSS 9.8, one shared HS256 key across all deployments
- The originate function passes a System parameter to Asterisk for code execution
- Fixed in commit b97dbaf; public proof-of-concept code exists
- Shadowserver reported first exploitation evidence on 9 September 2026
Read next
Security