CVE-2026-9586
Unauthenticated SQL Injection Leading to Remote Code Execution in Switchvox SMB
An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates the user-controlled PhoneIP value into PostgreSQL queries without sanitization or parameterization. An unauthenticated remote attacker can execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.
Coverage 2 sources
-
2026-09-02
CISA Cybersecurity Advisories
high
CISA Adds Seven Known Exploited Vulnerabilities to Catalog
CISA added 7 new vulnerabilities to its Known Exploited Vulnerabilities Catalog.
-
2026-09-02
Help Net Security
high
Exploitation of Sangoma Switchvox flaw is underway (CVE-2026-9586)
Exploitation of Sangoma Switchvox SQL injection flaw CVE-2026-9586 is underway.
Mentioned with
CVE-2026-48710 CVE-2026-49869 CVE-2026-59822 CVE-2026-82329
Also covered
- CVE-2026-86950 Apple iOS and iPadOS
- CVE-2023-6548 Cloud Software Group NetScaler ADC
- CVE-2023-25608 Fortinet FortiAP-W2
- CVE-2026-88772 Memory overflow vulnerability leading to Remote Code Execution or Denial of Service
- CVE-2026-88771 A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands