< BACK TO NEWS
importantSYS.SOURCE: The Hacker News2026-09-16T21:20:59+05:30

Critical Vulnerability in Issabel Framework Allows Unauthenticated OS Command Execution

A critical vulnerability (CVE-2026-89026) in the Issabel Framework allows unauthenticated attackers to execute OS commands via a hard-coded JWT signing key. A patch was released on August 1, 2026, to replace the vulnerable key with a configuration-stored alternative.

A critical security flaw in Issabel Framework, a web-based framework for the open-source unified communications PBX software, has come under active exploitation.

The vulnerability in question is CVE-2026-89026 (CVSS v3.1 score: 9.8/CVSS v4.0 score: 9.3), which can allow an unauthenticated remote attacker to execute arbitrary operating system (OS) commands by taking advantage of a hard-coded

Read original article

*** END OF TRANSMISSION ***