Výsledky hledání

výrobce: Issabel× téma: identita× v celém archivu zrušit filtry

1 karet z 1 položek CZ · EN/orig

1

Issabel Framework Hard-coded JWT Key RCE via pbxapi/manager/originate

Classification: Critical, Solution: Official Fix, Exploit Maturity: High, CVSSv4.0: 9.3, CVEs: CVE-2026-89026, Summary: The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS256 JWT signing key in the pbxapi index.php file that is identical across every installation, allowing unauthenticated remote attackers to forge valid bearer tokens. Attackers can use the forged token to call the manager originate endpoint with the System…

EPSS 0.01 CVSS 9.3 CVE-2026-89026 Issabel FI

tg: zneužíváno tg: zranitelnost tp: identita

· NCSC-FI · Issabel Framework Hard-coded JWT Key RCE via pbxapi/manager/originate