Critical severity9.8CISA KEVNVD Advisory· Published Jul 17, 2026· Updated Sep 3, 2026
CVE-2026-9586
CVE-2026-9586
Description
An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with and directly concatenates the user-controlled PhoneIP value into PostgreSQL queries without sanitization or parameterization. An unauthenticated remote attacker can execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: = 8.3 (104997)
Patches
Vulnerability mechanics
References
4- horizon3.ai/attack-research/disclosures/cve-2026-9586-sangoma-switchvox-rce/nvdExploitThird Party Advisory
- labs.sra.io/posts/switchvox/nvdThird Party Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdThird Party AdvisoryUS Government Resource
- sangomakb.atlassian.net/wiki/spaces/Switchvox/pages/1802371073/Switchvox+-+Release+Notes+Version+8.4.0.2+July+14+2026nvdRelease Notes
News mentions
8- ⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and MoreThe Hacker News · Sep 7, 2026
- Week in review: Claude accounts compromised through infostealer, Patch Tuesday forecastHelp Net Security · Sep 6, 2026
- Sangoma Switchvox Vulnerabilities Exploited in the WildSecurityWeek · Sep 4, 2026
- Hackers Actively Exploiting Sangoma Switchvox VoIP Platform RCE Flaw in AttacksCyber Security News · Sep 3, 2026
- CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto MinersThe Hacker News · Sep 3, 2026
- Exploitation of Sangoma Switchvox flaw is underway (CVE-2026-9586)Help Net Security · Sep 2, 2026
- Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without CredentialsThe Hacker News · Sep 2, 2026
- CISA Adds Seven Known Exploited Vulnerabilities to CatalogCISA Alerts