CVE-2026-9586 is a critical unauthenticated SQL injection vulnerability in Sangoma Switchvox SMB Edition versions prior to 8.4.0.2, affecting the /pa endpoint which processes PolycomIPPhone XML content. A remote unauthenticated attacker can send a single crafted HTTP request to inject arbitrary PostgreSQL commands, achieving remote code execution on the PBX server. This vulnerability is confirmed in CISA's Known Exploited Vulnerabilities catalog with active exploitation in the wild.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: DIRECT_NETWORK
CVE Published: 2026-07-17
Added to CISA KEV: 2026-09-02 47 DAYS BETWEEN CVE AND KEV
CVE-2026-9586 is a critical unauthenticated SQL injection vulnerability affecting Sangoma Switchvox SMB Edition, specifically version 8.3 (104997). The vulnerability resides within the `/pa` HTTP endpoint, which is designed to process phone notification requests. Because the application fails to properly sanitize or parameterize user-controlled input (specifically XML content containing a `PhoneIP` value) before concatenating it into backend PostgreSQL database queries, a remote, unauthenticated attacker can execute arbitrary SQL statements. This flaw is highly significant because it can be leveraged to achieve remote code execution (RCE) on the affected appliance [1][2].
CVE-2026-9586 is a critical unauthenticated SQL injection vulnerability in Sangoma Switchvox SMB Edition that allows a remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database and achieve remote code execution without authentication or user interaction. The vulnera…
CVEs. CVE-2026-9586. TrendingPoCFeedly KEVCISA KEV.Summary. An unauthenticated SQL injection vulnerability in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with
CVE-2026-9586. Sangoma Switchvox SQL Injection Vulnerability: Sangoma Switchvox contains a SQL injection vulnerability which allows an ...
The vulnerability is listed in CISA’s KEV catalog. Due to the absence of authentication required and the ability to reach the vulnerable endpoint over the network, the likely attack vector is an unauthenticated remote attacker sending crafted XML to the /pa service. Generated by OpenCVE AI on Septem…
Description. An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes ...