Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution
Executive Summary
A critical flaw (CVE‑2026‑89026) in the Issabel Framework, a web‑based component of the open‑source unified communications PBX, is actively exploited. The vulnerability, with CVSS v3.1 score 9.8 and v4.0 score 9.3, allows an unauthenticated remote attacker to execute arbitrary OS commands via a hard‑coded flaw. The Hacker News reports ongoing exploitation.
Intelligence Metadata - Source Publisher: The Hacker News - Published Date: 2026-09-16T15:50:59+00:00 - Category: threat-intel
Original Description: A critical security flaw in Issabel Framework, a web-based framework for the open-source unified communications PBX software, has come under active exploitation. The vulnerability in question is CVE-2026-89026 (CVSS v3.1 score: 9.8/CVSS v4.0 score: 9.3), which can allow an unauthenticated remote attacker to execute arbitrary operating system (OS) commands by taking advantage of a hard-coded
"Fortune favours the brave."
— Virgil