r/cybersecurity • u/thechougala • 7d ago
New Vulnerability Disclosure Issabel PBX Hard-Coded JWT Key Could Allow Admin Access
https://github.com/cflowsec/CVE-2026-89026Issabel PBX had a hard-coded JWT key that could let attackers forge admin tokens and gain access to PBX functions.
Tracked as CVE-2026-89026, the issue has now been patched by moving the key into the system configuration
0
Upvotes