Issabel A.I CyberSecurity Scoring
Issabel
Company Information
Website:http://www.issabel.com
Employees number:12
Number of followers:1,596
NAICS:517
Industry Type:Telecommunications
Homepage:issabel.com
Issabel Risk Score (AI oriented)
Between 700 and 749
IssabelTelecommunications
Updated:
16/09/2026
16/09/2026
747/1000
Moderate
Ba
Issabel Global Score (TPRM)
xxxx
IssabelTelecommunications
Score locked

IssabelModerate
Current Score
747Ba (MODERATE)
01000
1 incidents
-4 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
751
Vulnerability
09 Sep 2026 • Issabel
Issabel: Critical Issabel PBX Command Execution Vulnerability Exploited in the Wild
Critical Issabel PBX Vulnerability (CVE-2026-89026) Actively Exploited in the Wild
747
CRITICAL-4
ISS1789568674
Critical Issabel PBX Vulnerability (CVE-2026-89026) Actively Exploited in the Wild
A critical vulnerability in the Issabel Framework, which powers Issabel PBX deployments, is under active exploitation. Tracked as CVE-2026-89026 (CVSS v4: 9.3), the flaw allows unauthenticated remote attackers to execute arbitrary OS commands on vulnerable servers by forging authentication tokens.
The vulnerability stems from a hard-coded HS256 JSON Web Token (JWT) signing key embedded in the `pbxapi/index.php` file, present across affected installations. Attackers can generate a malicious bearer token, bypassing authentication, and submit requests to exposed API endpoints specifically the `pbxapi/manager/originate` endpoint, which interacts with the Asterisk Manager Interface. This enables command execution under the Asterisk service account, potentially leading to malware deployment, data theft, or lateral movement within a network.
Exploitation was first observed by the Shadowserver Foundation on September 9, 2026, targeting internet-exposed Issabel PBX systems. The flaw (CWE-321) poses a severe risk due to its low attack complexity, requiring no user interaction or prior access.
Affected versions include Issabel Framework releases before commit `b97dbaf0b71c1c36f841e672b664afbeb02773bd`. Organizations are advised to patch immediately, verify the removal of the hard-coded key, and restrict access to PBX administration interfaces. Security teams should monitor logs for suspicious token activity, unusual `originate` requests, or unauthorized command execution.
VulnCheck has added the vulnerability to its Known Exploited Vulnerabilities database, emphasizing the urgency of remediation.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
AUGUST 2026
751
JULY 2026
751
JUNE 2026
751
MAY 2026
751
APRIL 2026
751
MARCH 2026
751
FEBRUARY 2026
751
JANUARY 2026
751
DECEMBER 2025
751
NOVEMBER 2025
751
OCTOBER 2025
751
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Issabel ??
What was Issabel's A.I Rankiteo Cyber Score in August 2026 ??
What was Issabel's A.I Rankiteo Cyber Score in July 2026 ??
What was Issabel's A.I Rankiteo Cyber Score in June 2026 ??
What was Issabel's A.I Rankiteo Cyber Score in May 2026 ??
What was Issabel's A.I Rankiteo Cyber Score in April 2026 ??
What was Issabel's A.I Rankiteo Cyber Score in March 2026 ??
What was Issabel's A.I Rankiteo Cyber Score in February 2026 ??
What was Issabel's A.I Rankiteo Cyber Score in January 2026 ??
What was Issabel's A.I Rankiteo Cyber Score in December 2025 ??
What was Issabel's A.I Rankiteo Cyber Score in November 2025 ??
What was Issabel's A.I Rankiteo Cyber Score in October 2025 ??
What is the average per-incident point impact on Issabel's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Issabel ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Issabel's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?