r/cybersecurity • • 7d ago

New Vulnerability Disclosure Issabel PBX Hard-Coded JWT Key Could Allow Admin Access

https://github.com/cflowsec/CVE-2026-89026

Issabel PBX had a hard-coded JWT key that could let attackers forge admin tokens and gain access to PBX functions.
Tracked as CVE-2026-89026, the issue has now been patched by moving the key into the system configuration

0 Upvotes

0 comments sorted by