External risk intelligence

Issabel PBX Hard-Coded JWT Key Allows Remote Command Execution.

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-89026

Issabel PBX is a unified communications and VoIP management platform. These systems are commonly deployed as public-facing gateways or managed via web interfaces reachable over the internet to support remote PBX administration and telephony services, making the management API a typical, intentionally internet-exposed component.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A security vulnerability has been identified in the Issabel Framework, which supports Issabel PBX software. This issue involves a predictable signing key that could allow unauthenticated attackers to create valid security tokens. These forged tokens could potentially be used to execute arbitrary operating system commands on the affected systems, posing a significant risk to those running the software.

  • Predictable key allows forged access tokens.
  • Attackers can execute OS commands remotely.
  • Confirm if Issabel PBX is in use.

Attack Path

How an attacker could exploit the issue

An attacker can remotely forge a valid access token for the Issabel Framework without needing any credentials. This is possible because a shared, hard-coded secret key is used for signing JSON Web Tokens (JWT). By creating a forged token, an attacker can then call a specific API endpoint. This allows them to send commands to the underlying Asterisk system, enabling the execution of arbitrary operating system commands with the privileges of the Asterisk user.

  • No authentication required to start.
  • Forged token calls a vulnerable API endpoint.
  • Arbitrary OS command execution is possible.

Live Threat

Current exploitation, exposure, and threat context

The Issabel PBX management interface could allow unauthenticated attackers to execute arbitrary operating system commands. This is possible when an attacker can forge a valid bearer token due to a hard-coded signing key, enabling them to call a specific API endpoint that passes commands to the underlying Asterisk system.

  • Arbitrary OS command execution.
  • Forged tokens may call management API.
  • Compromise of the PBX system.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Issabel PBX and its underlying framework are likely managed by platform or infrastructure teams, with security teams overseeing network exposure. The first step is to locate all Issabel installations, determine their internet reachability and business criticality, and identify the specific system owners responsible for each. This information will guide the prioritization and planning of remediation efforts.

  • Platform or infrastructure teams own remediation.
  • Verify internet exposure and criticality of installations.
  • Coordinate updates or apply temporary mitigations.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Issabel Framework and how does it relate to Issabel PBX?

Issabel Framework is the core web-based infrastructure that powers Issabel PBX, a platform used for managing Voice over IP (VoIP) telephony and unified communications. The framework provides the management interface and API endpoints that administrators use to configure system services, including the underlying Asterisk software that handles call routing and phone system functionality.

What does CWE-321 mean in the context of CVE-2026-89026?

CWE-321 refers to the use of a hard-coded cryptographic key. In this CVE, the Issabel Framework uses the same secret key across every installation to sign JSON Web Tokens (JWT). Because this key is predictable and identical for all users, an attacker can generate their own valid authentication tokens without needing legitimate credentials, essentially bypassing the system's security login process entirely.

How does an attacker trigger this vulnerability?

An attacker triggers this by using the known hard-coded key to sign a custom, forged JWT. With this token, they can interact with the pbxapi endpoint and call the manager originate function. It is important to note that simply visiting the web interface does not trigger the bug; the attacker must specifically send crafted requests to the API that use a forged token to successfully execute arbitrary commands.

Is my system at risk if it is not internet-facing?

Halo Surface Signal indicates that Issabel PBX is frequently deployed as a public-facing gateway or managed via web interfaces reachable over the internet. While internal systems have a smaller attack surface, any instance of the software remains susceptible if an attacker gains access to the local network. Prioritize auditing systems that are directly exposed to the internet, as these are the most accessible targets for this specific flaw.

How should I respond if I am running Issabel PBX?

Begin by creating an inventory of all Issabel installations to identify which systems are currently active and where they reside in your network. Coordinate with the infrastructure or platform teams responsible for these servers to verify their reachability. Review the official project commits to confirm if your version contains the fix, and prioritize patching or isolating any high-criticality systems that are accessible from the internet.

References