Vulnerability record · CVE-2026-9586 · published 17 July 2026
CVE-2026-9586: Sangoma Switchvox unauthenticated SQL injection in /pa endpoint
Sangoma · Switchvox
Sangoma Switchvox SMB Edition 8.3 (104997) fails to sanitize the PhoneIP value from XML content beginning with <PolycomIPPhone> before concatenating it into PostgreSQL queries at the /pa endpoint. An unauthenticated remote attacker can run arbitrary SQL against the backend database with a single crafted request. The flaw is critical because it requires no credentials or user interaction and can lead to remote code execution.
Description
An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates the user-controlled PhoneIP value into PostgreSQL queries without sanitization or parameterization. An unauthenticated remote attacker can execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:
Automated analysis
critical priorityUnauthenticated network-reachable SQL injection with RCE potential, a public exploit reference, and CISA KEV listing with a near-term remediation due date.
What it is
Sangoma Switchvox SMB Edition 8.3 (104997) fails to sanitize the PhoneIP value from XML content beginning with <PolycomIPPhone> before concatenating it into PostgreSQL queries at the /pa endpoint. An unauthenticated remote attacker can run arbitrary SQL against the backend database with a single crafted request. The flaw is critical because it requires no credentials or user interaction and can lead to remote code execution.
Impact
An attacker gains full read/write access to the backend PostgreSQL database and, per the description, can achieve remote code execution on the Switchvox host. This can expose or destroy telephony data and give the attacker a foothold on the appliance.
Attack surface
Reachable over the network via the /pa endpoint by sending crafted XML beginning with <PolycomIPPhone>; the CVSS vector shows PR:N and UI:N, so no authentication or user interaction is needed. Any internet- or network-exposed Switchvox instance with this endpoint is a candidate target.
Exploitation
CVE-2026-9586 is listed in CISA KEV (added 2026-09-02, due 2026-09-05) and a public exploit reference is tagged Exploit, indicating active exploitation. EPSS is 0.11845 (95.9th percentile), so exploitation is plausible and observed.
What to do
- Apply the vendor fix by upgrading to Switchvox 8.4.0.2 (July 14, 2026) or later per the release notes.
- If patching is not immediately possible, restrict network access to the /pa endpoint and remove internet exposure of the Switchvox appliance.
- Follow CISA BOD 26-04 guidance and the KEV required action, including forensics triage; discontinue use if mitigations are unavailable.
- Review and rotate any credentials or secrets stored in or reachable from the Switchvox PostgreSQL backend.
- Monitor vendor and CISA advisories for updated mitigation instructions.
Detection
- Inspect HTTP requests to /pa for XML bodies beginning with <PolycomIPPhone> and unexpected or malformed PhoneIP values.
- Look for SQL syntax, UNION, stacked-query or comment patterns in the PhoneIP parameter within web or WAF logs.
- Monitor PostgreSQL logs for anomalous queries or errors originating from the Switchvox application host.
- Hunt for unexpected outbound connections or new processes on the Switchvox appliance that could indicate post-exploitation RCE.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2026-9586 to the Known Exploited Vulnerabilities catalog on 2 September 2026 as "Sangoma Switchvox SQL Injection Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 5 September 2026.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://labs.sra.io/posts/switchvox/ | Third Party Advisory |
| https://sangomakb.atlassian.net/wiki/spaces/Switchvox/pages/1802371073/Switchvox+-+Release+Notes+Version+8.4.0.2+July+14 | Release Notes |
| https://horizon3.ai/attack-research/disclosures/cve-2026-9586-sangoma-switchvox-rce/# | ExploitThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-9586 | Third Party AdvisoryUS Government Resource |
Track CVE-2026-9586 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-9586), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.