{"id":244132,"date":"2026-09-17T05:23:12","date_gmt":"2026-09-17T10:23:12","guid":{"rendered":"https:\/\/lifeboat.com\/blog\/2026\/09\/attackers-exploit-issabel-framework-flaw-enabling-unauthenticated-os-command-execution"},"modified":"2026-09-17T05:23:12","modified_gmt":"2026-09-17T10:23:12","slug":"attackers-exploit-issabel-framework-flaw-enabling-unauthenticated-os-command-execution","status":"publish","type":"post","link":"https:\/\/lifeboat.com\/blog\/2026\/09\/attackers-exploit-issabel-framework-flaw-enabling-unauthenticated-os-command-execution","title":{"rendered":"Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution"},"content":{"rendered":"<p><a class=\"aligncenter blog-photo\" href=\"https:\/\/lifeboat.com\/blog.images\/attackers-exploit-issabel-framework-flaw-enabling-unauthenticated-os-command-execution.jpg\"><\/a><\/p>\n<p>A critical security flaw in <a href=\"https:\/\/github.com\/IssabelFoundation\/framework\" target=\"_blank\">Issabel Framework<\/a>, a web-based framework for the open-source unified communications PBX software, has come under active exploitation.<\/p>\n<p>The vulnerability in question is <strong><a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-89026\" target=\"_blank\">CVE-2026\u201389026<\/a><\/strong> (CVSS v3.1 score: 9.8\/CVSS v4.0 score: 9.3), which can allow an unauthenticated remote attacker to execute arbitrary operating system (OS) commands by taking advantage of a hard-coded JSON Web Token (JWT) signing key.<\/p>\n<p>The Issabel Framework \u201ccontains a hard-coded HS256 JWT signing key in the pbxapi index.php file that is identical across every installation, allowing unauthenticated remote attackers to forge valid bearer tokens,\u201d VulnCheck <a href=\"https:\/\/www.vulncheck.com\/advisories\/issabel-pbx-hard-coded-jwt-key-rce-via-pbxapi-manager-originate\" target=\"_blank\">said<\/a> in an alert.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A critical security flaw in Issabel Framework, a web-based framework for the open-source unified communications PBX software, has come under active exploitation. The vulnerability in question is CVE-2026\u201389026 (CVSS v3.1 score: 9.8\/CVSS v4.0 score: 9.3), which can allow an unauthenticated remote attacker to execute arbitrary operating system (OS) commands by taking advantage of a hard-coded [\u2026]<\/p>\n","protected":false},"author":427,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1523,1492],"tags":[],"class_list":["post-244132","post","type-post","status-publish","format-standard","hentry","category-computing","category-security"],"_links":{"self":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/244132","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/users\/427"}],"replies":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/comments?post=244132"}],"version-history":[{"count":0,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/244132\/revisions"}],"wp:attachment":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/media?parent=244132"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/categories?post=244132"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/tags?post=244132"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}