Exploited Issabel PBX flaw uses a shared hardcoded key to run commands unauthenticated
Attackers are exploiting a critical flaw in Issabel Framework, the web interface for the open-source Asterisk-based phone system. Tracked as CVE-2026-89026 and scored 9.8, the flaw stems from a hardcoded token-signing key that is identical across every installation, so an unauthenticated attacker can forge a valid access token, call the system's call-origination endpoint, and make Asterisk run arbitrary operating-system commands. Researchers at VulnCheck flagged it, and the Shadowserver Foundation first saw exploitation on September 9. A patch released on August 1 replaces the shared key with a unique per-installation key. Exposed, unpatched phone systems should be treated as urgent given the low barrier to attack.
- Check
- Update Issabel Framework to the patched version that replaces the shared signing key, and take the phone system's web interface off the public internet, restricting it to trusted management networks.
- Affected
- Organizations running internet-exposed Issabel Framework phone systems (CVE-2026-89026); because the signing key is identical everywhere, an unauthenticated attacker can forge a token and run operating-system commands, and exploitation is underway.
- Fix
- Patch to remove the hardcoded key, restrict and monitor access to the PBX web and management interfaces, hunt for forged-token requests and unexpected command execution, and rotate credentials if compromise is suspected.