Issabel Framework의 취약점으로 OS 명령어 실행이 가능해졌다.
Issabel Framework에서 심각한 보안 취약점이 발견되어 활발히 악용되고 있다. 이 취약점은 CVE-2026-89026으로, 인증되지 않은 원격 공격자가 하드코딩된 값을 이용해 임의의 운영 체제(OS) 명령어를 실행할 수 있다. CVSS v3.1 점수는 9.8이며, CVSS v4.0 점수는 9.3으로 심각성이 높다.
A vulnerability in Issabel Framework allows unauthenticated OS command execution.
A critical security flaw has been discovered in the Issabel Framework, leading to its active exploitation. The vulnerability, CVE-2026-89026, enables unauthenticated remote attackers to execute arbitrary operating system (OS) commands using hard-coded values. It has a CVSS v3.1 score of 9.8 and a CVSS v4.0 score of 9.3, indicating a high severity level.