CVE Tools
Back to feed
Exploited in the wild Issabel PBX rce Issabel Framework network-edge

Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution

The Hacker News·By The Hacker News··1 min read
CVE Tools coverage

Attackers are exploiting CVE-2026-89026 in Issabel Framework, affecting Issabel PBX, to execute operating-system commands remotely without authentication. The flaw uses a JWT signing key shared across installations, allowing forged tokens to invoke Asterisk functionality and run commands as the Asterisk user. A patch released on August 1, 2026 moves the key into "/etc/issabel.conf"; users should apply the latest fixes.

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store