← Back to CVE intelligence
CVE intelligence

CVE-2026-89026

Vulnerability intelligence

Published Sep 15, 2026Sources checked Oct 3, 2026
9.8CRITICALCVSS out of 10
What this means

Exploitation reported: act now

The Hacker News reports exploitation in the wild. This is separate from CISA KEV membership.

Public exploit: Not collected. Review the linked vendor advisory and apply the mitigation or fixed release for your affected product.

CISA KEVNot listedBased on the latest collected catalog
EPSS0.7%Estimated 30-day exploitation probability
Ransomware useNot markedCISA KEV ransomware field
Threat actors0Source-linked actor relationships
Overview

What is CVE-2026-89026?

The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS256 JWT signing key in the pbxapi index.php file that is identical across every installation, allowing unauthenticated remote attackers to forge valid bearer tokens. Attackers can use the forged token to call the manager originate endpoint with the System application parameter, causing Asterisk to execute arbitrary OS commands as the Asterisk user. Exploitation evidence was first observed by the Shadowserver Foundation on 2026-09-09.