
Issabel PBX JWT Key Flaw Enables Unauthenticated Remote Code Execution
A critical vulnerability in the Issabel Framework could allow unauthenticated remote attackers to execute arbitrary operating-system commands on affected Issabel PBX deployments by exploiting a hard-coded JSON Web Token signing key. Tracked as CVE-2026-89026, the vulnerability affects Issabel Framework versions prior to commit b97dbaf0b71c1c36f841e672b664afbeb02773bd. The issue carries a CVSS v4 score of 9.3 and is […]
The post Issabel PBX JWT Key Flaw Enables Unauthenticated Remote Code Execution appeared first on Cyber Security News.