Impact
The Iss HS256 JWT signing key that is identical in every installation. Attackers can generate a valid bearer token without authentication and then call the pbxapi/manager/originate API endpoint with the System application parameter. The Asterisk engine executes the supplied command string as the Asterisk user, giving the attacker arbitrary OS command execution on the host. Shadowserver observed active exploitation on 2026-09-09, confirming real‑world use.
Affected Systems
The vulnerability affects all deployments of Issabel Foundation’s Issabel Framework that use the pbxapi index.php file prior to the fix incorporated in commit b97dbaf0b71c1c36f841e672b664afbeb02773bd. Any installation that has not applied this patch is vulnerable.
Risk and Exploitability
The CVSS score of 9.3 reflects a high severity, and the EPSS score of 0.00521 (less than 1%) indicates a very low but nonzero exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Attackers can remotely forge a bearer token without authentication and evolve it over HTTP or HTTPS to the pbxapi/manager/originate endpoint, causing Asterisk to run arbitrary OS commands as the Asterisk user. Because the flaw bypasses authentication, remote exploitation is straightforward.
OpenCVE Enrichment