CVE-2026-9586: Sangoma Switchvox SQL Injection Vulnerability
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2026-09-02. EPSS: 19% chance of exploitation in the next 30 days.
An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates the user-controlled PhoneIP value into PostgreSQL queries without sanitization or parameterization. An unauthenticated remote attacker can execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.
Affected products
- Sangoma Switchvox: from 8.2.2.1, before 8.4.0.2 (fixed in 8.4.0.2)
Published 2026-07-17. Last modified 2026-09-03.