The images in this article were generated with artificial intelligence. How we publish
A serious vulnerability in the Issabel Framework web framework - identified as CVE-2026-89026- is being actively exploited and allows non-authenticated remote attackers to run commands in the operating system of the Asterisk running equipment. The failure has a high severity score (CVSS v3.1: 9.8; CVSS v4.0: 9.3) and is based on poor JWT key management: a HS256 key encoded in a fixed and common way to all facilities allowed an attacker to make valid tokens and call the management API to cause Asterisk to run commands with the asterisk user.
Confirmed facts: the vulnerability identified as CVE-2026-89026 exists in the pbxapi index.php file of the Issabel Framework and uses a coded HS256 key ("da893kasdfam43k29akdkfaFsdfhj23rasdf") that is identical between installations; this weakness allows to forge valid tokens bearer and, through the endpoint / pbxapi / manager / origate with the System application parameter, cause Asterisk to execute system orders with the user's privileges. The supplier published a correction on 1 August 2026 that replaces the embedded key with a read key from / etc / issabel.conf. In addition, the Shadowserver Foundation reported on active exploitation observations since 9 September 2026. These points form the core of what is confirmed so far.

How the failure works technically: JWT with HS256 algorithm uses a single shared secret key to sign and verify tokens. If that key is known or identical in all facilities, anyone who knows it can create a token with the fields needed to pass the bearer token-based authentication. In Issabel, the vulnerable endpoint allows you to start a call or run the System application in Asterisk; when using that application, Asterisk runs system commands as the asterisk user. The combination of forged + endpoint originate token produces remote execution of commands without valid system credentials.
Who are affected: all Issabel Framework facilities that have not been updated since the correction of 1 August 2026 and which expose the affected endpoint (e.g. in public interfaces or in networks with external access) are at risk. PBX installed in poorly segmented environments, with HTTP / HTTPS ports exposed or without API access restrictions, are the most vulnerable. They are also at risk for integration that uses this API for remote management and that they assume that JWT is a secure identity guarantee.
The practical consequences vary according to the configuration, but are relevant: the execution of commands as an asterisk user allows you to modify Asterisk configurations, manipulate recording files, establish limited persistence (e.g., chronjobs under the asterisk user's permission), deploy call-listening or relay tools, move laterally on the network if there are additional privileges, or prepare further steps of privilege climbing. These consequences are plausible and should be treated as a real risk although the exact scope of the attacks observed (who are the attackers and how many facilities have been compromised) is not publicly documented.
What is known and what is not:: It is confirmed that vulnerability exists, that it was patched and that Shadowserver detected active exploitation from 9 September 2026. There is no verified public information on the exact operating technique used in the field, the motivation of the attackers, large-scale shared commitment indicators, or the number of facilities affected. The attackers may be automating the discovery of exposed endpoints to exploit non-patch facilities, but this is an estimate based on the typical pattern of such failures.
Immediate and concrete actions to be taken by a system manager: update without delay the Issabel version containing the correction published on August 1, 2026; confirm that the installation now loads a JWT key from / etc / issabel.conf and that that key is unique per server. If you cannot update immediately, block access to the vulnerable endpoint at firewall level or scorer level (filter / pbxapi / manager / originate and restrict HTTP / S access to the management panel only to trusted PIs). Disable the API if not used.
In addition to updating and blocking access, implement the following operational steps: review the web access and Asterisk records for inputs to / pbxapi / manager / originate and Authentication checks: Bearer; inspect / var / log / asterisk / and system files in search of unusual orders executed by the asterisk user and new files or chronJobs; corroborate the integrity of binary and critical configurations; and, if suspicious activity is detected, consider rebuilding the affected host from a known clean image and restore settings from verified backups.
For concrete detection and monitoring I suggest looking for patterns in logs: attempts to access / pbxapi / manager / origate, presence of tokens bear in HTTP headers from unauthorized origins, and system commands executed by Asterisk's children processes. Integrate these searches into your IDS / IPS rules and your IMS for early alerts.
Medium-term mitigation measures: ensure that JWT keys are not encoded in source code; encourage safe storage in configuration files with restricted permissions or in secret management modules. Apply less privileged principles: reduce the asterisk user's permissions as much as possible; segment the network to make PBX management interfaces accessible only from administrative subnetworks; implement strong authentication for administrative interfaces and mandatory critical change audit.

If you manage suppliers or customers with PBX in the cloud, require stamping and checking and closing of unused APIs. Backup and restoration tests should be part of the response plan, and in the face of signs of commitment act as if persistence and side access had been obtained.
For more technical information and good practice on the management of JWT and its safety see the recommendations of OWASP on JSON Web Tokens and the official pages of the Issabel and Shadowserver project: OWASP JWT Cheat Sheet, Issabel Project and Shadowserver Foundation. These sources provide additional context and guidance for operational adjustments and detection.
In short: it is a serious remote operating vulnerability with published patch; the immediate priority is to update, block access to the affected API and look for compromise indicators in your systems. Since the active operation has been observed, treat the facilities exposed as high risk until their cleaning and isolation is confirmed.
Related
More news on the same subject.

GhostAction Campaign commits maintenance accounts and inserts workflows to exfilter secrets
Security researchers have re-detected a massive credentials theft campaign that exploits open source project maintainer accounts to insert malicious workflows in GitHub reposito...

Florida, Iowa, Montana and Nebraska sue TP-Link Systems for security and source of routers
On October 6, four State Attorney General filed complaints against TP- Link Systems in U.S. state courts - in addition to a previous Texas lawsuit - for business practices relat...

FBI and six countries link Integrity Technology Group to entity post theft in SE Asia
On October 8, the FBI and agencies in six countries issued a joint warning that assigns to a Chinese company, Integrity Technology Group, a sustained series of intrusions whose ...

Campaign with LLM and ARTEX attacks South Korean financial institutions and exfilters data
Security researchers have documented a campaign directed against South Korean financial institutions using language-driven attack tools to automate intrusions and data extractio...

ChainDrop campaign exposes tensorlake in npm; version 0.5.144 withdrawal
A package of npm called tensorlake, an SDK in TypeScript oriented to Tensorlake applications and services, was engaged in a supply chain campaign linked to the attack family kno...

Cyber risk in 2026 moves to workflows and IA, according to Voice of the CISO
The data added by five editions of the Voice of the CISO study - including the most recent findings of 2026 - draw a less intense change than risk location: the threat is moving...

Phishing BitB points to advertising professionals and account managers to steal MFA
Security researchers have described a phishing campaign for advertising professionals and account managers that uses a human-operated platform to mimic ad products linked to IA ...