Critical RCE Flaw in Issabel Framework Actively Exploited
A severe unauthenticated command injection vulnerability in Issabel Framework is under active attack. Organizations using the open-source PBX platform should take immediate action.
TL;DR
- CVE-2026-89026 is a critical RCE flaw in Issabel Framework with CVSS scores of 9.8 (v3.1) and 9.3 (v4.0)
- The vulnerability allows unauthenticated attackers to execute arbitrary OS commands
- Attackers are actively exploiting this flaw in the wild
- Issabel Framework is used in open-source unified communications and PBX systems
- Organizations should immediately apply patches or isolate affected systems
Security researchers have identified active exploitation of a critical vulnerability in Issabel Framework, a popular open-source platform for unified communications and PBX systems. The flaw, tracked as CVE-2026-89026, enables remote attackers to execute arbitrary operating system commands without authentication.
With a CVSS v3.1 score of 9.8 and CVSS v4.0 score of 9.3, this represents a severe risk to organizations deploying vulnerable versions of the software. The vulnerability stems from a hard-coded implementation issue that attackers can leverage to gain complete system control.
Technical Impact
- The vulnerability allows unauthenticated remote command execution with the same privileges as the web server process
- Attackers can install malware, steal sensitive data, or use compromised systems for further attacks
- No user interaction or authentication is required to exploit this flaw
- The hard-coded nature of the vulnerability makes it particularly dangerous across deployments
Affected Systems and Recommendations
- Organizations running Issabel Framework versions prior to the latest patched release are at risk
- Systems used for VoIP, unified communications, and PBX services should be prioritized for assessment
- Immediate actions include applying vendor patches, implementing network segmentation, and monitoring for suspicious activity
- Consider temporary isolation of affected systems if patching is not immediately possible
- Review system logs for evidence of exploitation, including unusual command execution patterns
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.