VYPR
Unrated severityNVD Advisory· Published Jul 17, 2026· Updated Jul 17, 2026

Unauthenticated SQL Injection Leading to Remote Code Execution in Switchvox SMB

CVE-2026-9586

Description

An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with and directly concatenates the user-controlled PhoneIP value into PostgreSQL queries without sanitization or parameterization. An unauthenticated remote attacker can execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.

Affected products

2

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.