Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Labour holds No 10 drinks party for donors amid growing calls for donations cap | Labour

    September 16, 2026

    Andy Burnham and his chancellor have a battle on their hands

    September 16, 2026

    Claude comes for Gemini with its own take on Docs and Slides

    September 16, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Labour holds No 10 drinks party for donors amid growing calls for donations cap | Labour
    • Andy Burnham and his chancellor have a battle on their hands
    • Claude comes for Gemini with its own take on Docs and Slides
    • Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution
    • Anchorage Adds Etherlink, Tokenized Uranium Custody
    • Part-human part-mouse brain developed in science breakthrough
    • Texas Oil and Gas Regulator Doubles Down and Defies State Legislature
    • John Deere dominates farm machinery. Now it’s moving deeper into farm data and AI.
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, September 16
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 16, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananSep 16, 2026Vulnerability / Web Security

    A critical security flaw in Issabel Framework, a web-based framework for the open-source unified communications PBX software, has come under active exploitation.

    The vulnerability in question is CVE-2026-89026 (CVSS v3.1 score: 9.8/CVSS v4.0 score: 9.3), which can allow an unauthenticated remote attacker to execute arbitrary operating system (OS) commands by taking advantage of a hard-coded JSON Web Token (JWT) signing key.

    The Issabel Framework “contains a hard-coded HS256 JWT signing key in the pbxapi index.php file that is identical across every installation, allowing unauthenticated remote attackers to forge valid bearer tokens,” VulnCheck said in an alert.

    “Attackers can use the forged token to call the manager ‘/pbxapi/manager/originate’ endpoint with the System application parameter, causing Asterisk to execute arbitrary OS commands as the Asterisk user.”

    Cybersecurity

    A patch for the vulnerability was pushed on August 1, 2026, and plugs the flaw by replacing the hard-coded JWT key (“da893kasdfam43k29akdkfaFFlsdfhj23rasdf”) with a JWT key stored in the “/etc/issabel.conf” file.

    According to the cybersecurity company, the Shadowserver Foundation first observed exploitation of CVE-2026-89026 on September 9, 2026. That said, there are currently no details on how the vulnerability is being abused in real-world attacks, who is behind them, and the scale of such efforts.

    Users of the Issabel Framework are advised to apply the latest fixes for optimal protection.

    Attackers Command Enabling Execution exploit Flaw Framework Issabel unauthenticated
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Hack-back programs could expose your security vendors

    The true cost of a ransomware attack, with and without BCDR

    N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security

    Microsoft says Copilot buttons still missing in classic Outlook

    Critical ScreenConnect flaw now actively exploited in attacks

    Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Labour holds No 10 drinks party for donors amid growing calls for donations cap | Labour

    September 16, 2026

    Andy Burnham and his chancellor have a battle on their hands

    September 16, 2026

    Claude comes for Gemini with its own take on Docs and Slides

    September 16, 2026

    Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution

    September 16, 2026
    Latest Posts

    What is Trump Media’s Truth API and why is it controversial?

    August 4, 2026

    How ProPublica Tested Hundreds of Omaha Homes for Lead — ProPublica

    August 4, 2026

    Golar LNG raises $600 million loan with FLNG business expansion in mind

    August 4, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Labour holds No 10 drinks party for donors amid growing calls for donations cap | Labour

    September 16, 2026

    Andy Burnham and his chancellor have a battle on their hands

    September 16, 2026

    Claude comes for Gemini with its own take on Docs and Slides

    September 16, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.