Critical Hardcoded JWT Key Flaw in Issabel PBX Framework Enables Remote Code Execution
A severe vulnerability, tracked as CVE-2026-89026 with a CVSS score of 9.8, was discovered in the pbxapi component of Issabel Framework, an open-source unified communications platform built on Asterisk. Every deployment shipped with the same hardcoded HS256 signing key, allowing any attacker who obtained it to forge valid authentication tokens for any installation worldwide. Using a crafted token, an attacker could invoke the management originate function, which passes unsanitized input directly to Asterisk for execution under its process privileges. Successful exploitation could enable toll fraud, theft of call recordings and voicemail, harvesting of extension credentials, and lateral movement into connected systems. The flaw was patched in upstream commit b97dbaf, and administrators are urged to apply the fix, rotate signing secrets, and audit logs for signs of compromise during the exposure window.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in