chiprook
← Security
SecuritySeptember 26, 2026, 17:00

Issabel Framework ships hardcoded JWT key in pbxapi (CVE-2026-89026)

The open-source Issabel Framework, built on Asterisk, shipped a single hardcoded HS256 signing key in its pbxapi component. Tracked as CVE-2026-89026 with a CVSS score of 9.8, the flaw lets attackers forge a bearer token and execute code on the Asterisk host; it was fixed in commit b97dbaf, with first exploitation evidence reported on 9 September 2026.

Issabel Framework ships hardcoded JWT key in pbxapi (CVE-2026-89026)
#Issabel#Asterisk
Read next
Security

Attackers exploit Issabel Framework flaw enabling unauthenticated OS command execution

Security

Active exploitation attempts target WSO2 API Manager JWT bypass

Security

Hardcoded MCP Credentials Found in Public GitHub Files

Security

Cisco Talos Launches CAIRN Framework to Classify AI-Driven Malware