The Issabel PBX system has a critical vulnerability that has already been exploited in attacks (CVE-2026-89026): an attacker can execute commands on the server without a username or password.
Issabel is an Asterisk-based PBX system used by companies to manage their calls, voicemail, and other communication services. Many small businesses have such a system installed on-site by a telecommunications or IT provider, even if they never access its administration panel. The CVE-2026-89026 vulnerability has been confirmed to be exploited in real-world attacks, and the Shadowserver Foundation has observed attacks on PBX systems directly exposed to the internet.
The issue stems from a signature key that is identical across all Issabel installations. With it, an attacker can create a valid access token on their own, without knowing any passwords, and can then instruct the control panel to execute commands on the server where it is running. Essentially, anyone who gains access to the control panel’s interface via the internet gains control over the server.
The fix was released by the developers and replaces the shared key with a unique one generated during each installation. Since the attack requires the control panel to be accessible from the internet, the second—and equally important—measure is to ensure that this panel is not directly exposed to the outside.
For a small business, a phone system is the kind of equipment that “just works” and that no one checks for years on end. It’s not something you fix yourself—it’s managed by the provider who installed it.
What you need to do:
- Ask the provider who installed your phone system whether they use Issabel (or Asterisk) and whether they have applied the update for CVE-2026-89026.
- Ask them to confirm that the PBX’s administration panel isn’t directly exposed to the internet, but is accessible only from the company’s network or via VPN.
- If you do not need access to the PBX from outside the company, keep it closed off from the outside.
The phone system is a forgotten box tucked away in the corner of the server room, but it has access to the company's network. A quick check with the provider shuts it down before it can be used.
This article was generated with AI assistance.