CVE-2026-9586
Sangoma Switchvox SQL Injection Vulnerability
Description
An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates the user-controlled PhoneIP value into PostgreSQL queries without sanitization or parameterization. An unauthenticated remote attacker can execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.
Description as published by the source, in English.
Key facts
- Published
- 2026-07-17
- Last modified
- 2026-09-03
- Assigned by
- 57dba5dd-1a03-47f6-8b36-e84e47d335d8
- CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H- Scored by
- nvd@nist.gov (NVD Primary)
- Probability of exploitation
-
0.4 %
higher than 34 %
of all known vulnerabilities
EPSS, next 30 days, model v2026.06.15 - Fix available
- Not registered in the sources
Actively exploited
CISA added this vulnerability to the Known Exploited Vulnerabilities catalogue on 2026-09-02, with a remediation deadline of 2026-09-05 for US federal agencies.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Affected products
| Vendor | Product | Versions | Status |
|---|---|---|---|
| Sangoma | Switchvox | ≥ 8.2.2.1, < 8.4.0.2 | Affected |
Weakness type
-
CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQ…
References
- https://labs.sra.io/posts/switchvox/
- https://sangomakb.atlassian.net/wiki/spaces/Switchvox/pages/1802371073/Switchvox+-+Releas…
- https://horizon3.ai/attack-research/disclosures/cve-2026-9586-sangoma-switchvox-rce/#
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-9586
Related at Berigo
Articles
-
Seven new KEV entries, three of them in open developer components
Mentions this CVE
2026-09-03
CISA added seven new vulnerabilities to its Known Exploited Vulnerabilities catalogue on 2 September 2026. Three of them sit in open components used …
-
CISA adds four exploited vulnerabilities to the KEV catalog
Same product
2026-02-03
The flaws affect Sangoma FreePBX, GitLab and SolarWinds Web Help Desk, spanning from 2019 to one published a week ago.
Does this affect you?
A vulnerability matters only if you run the product, in an affected version, somewhere an attacker can reach.