AllCyberNews

CVE-2026-9586

Unauthenticated SQL Injection Leading to Remote Code Execution in Switchvox SMB

CVSS 9.3 critical · Sangoma Switchvox SMB Edition · published 2026-07-17

An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates the user-controlled PhoneIP value into PostgreSQL queries without sanitization or parameterization. An unauthenticated remote attacker can execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.

Coverage 2 sources

  1. 2026-09-02 CISA Cybersecurity Advisories high CISA Adds Seven Known Exploited Vulnerabilities to Catalog

    CISA added 7 new vulnerabilities to its Known Exploited Vulnerabilities Catalog.

  2. 2026-09-02 Help Net Security high Exploitation of Sangoma Switchvox flaw is underway (CVE-2026-9586)

    Exploitation of Sangoma Switchvox SQL injection flaw CVE-2026-9586 is underway.

Mentioned with

CVE-2026-48710 CVE-2026-49869 CVE-2026-59822 CVE-2026-82329

Also covered