← Vulnerability feed

Vulnerability record · CVE-2026-9586 · published 17 July 2026

CVE-2026-9586: Sangoma Switchvox unauthenticated SQL injection in /pa endpoint

Sangoma · Switchvox

Sangoma Switchvox SMB Edition 8.3 (104997) fails to sanitize the PhoneIP value from XML content beginning with <PolycomIPPhone> before concatenating it into PostgreSQL queries at the /pa endpoint. An unauthenticated remote attacker can run arbitrary SQL against the backend database with a single crafted request. The flaw is critical because it requires no credentials or user interaction and can lead to remote code execution.

9.3 CVSS 4.0 Critical CISA KEV since 2 Sep 2026 EPSS 19% · top 2.8% CWE-89 · SQL injection
9.3CVSS 4.0 base score
19%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
4References, 1 tagged exploit
3 Sep 2026Last modified by NVD

Description

An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates the user-controlled PhoneIP value into PostgreSQL queries without sanitization or parameterization. An unauthenticated remote attacker can execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable SQL injection with RCE potential, a public exploit reference, and CISA KEV listing with a near-term remediation due date.

What it is

Sangoma Switchvox SMB Edition 8.3 (104997) fails to sanitize the PhoneIP value from XML content beginning with <PolycomIPPhone> before concatenating it into PostgreSQL queries at the /pa endpoint. An unauthenticated remote attacker can run arbitrary SQL against the backend database with a single crafted request. The flaw is critical because it requires no credentials or user interaction and can lead to remote code execution.

Impact

An attacker gains full read/write access to the backend PostgreSQL database and, per the description, can achieve remote code execution on the Switchvox host. This can expose or destroy telephony data and give the attacker a foothold on the appliance.

Attack surface

Reachable over the network via the /pa endpoint by sending crafted XML beginning with <PolycomIPPhone>; the CVSS vector shows PR:N and UI:N, so no authentication or user interaction is needed. Any internet- or network-exposed Switchvox instance with this endpoint is a candidate target.

Exploitation

CVE-2026-9586 is listed in CISA KEV (added 2026-09-02, due 2026-09-05) and a public exploit reference is tagged Exploit, indicating active exploitation. EPSS is 0.11845 (95.9th percentile), so exploitation is plausible and observed.

What to do

  • Apply the vendor fix by upgrading to Switchvox 8.4.0.2 (July 14, 2026) or later per the release notes.
  • If patching is not immediately possible, restrict network access to the /pa endpoint and remove internet exposure of the Switchvox appliance.
  • Follow CISA BOD 26-04 guidance and the KEV required action, including forensics triage; discontinue use if mitigations are unavailable.
  • Review and rotate any credentials or secrets stored in or reachable from the Switchvox PostgreSQL backend.
  • Monitor vendor and CISA advisories for updated mitigation instructions.

Detection

  • Inspect HTTP requests to /pa for XML bodies beginning with <PolycomIPPhone> and unexpected or malformed PhoneIP values.
  • Look for SQL syntax, UNION, stacked-query or comment patterns in the PhoneIP parameter within web or WAF logs.
  • Monitor PostgreSQL logs for anomalous queries or errors originating from the Switchvox application host.
  • Hunt for unexpected outbound connections or new processes on the Switchvox appliance that could indicate post-exploitation RCE.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2026-9586 to the Known Exploited Vulnerabilities catalog on 2 September 2026 as "Sangoma Switchvox SQL Injection Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 5 September 2026.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-9586 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

5.3CVE-2021-45310Sangoma switchvox information exposure vulnerabilitySangoma Technologies Corporation Switchvox Version 102409 is affected by an information disclosure vulnerability due to an improper access restrictio…EPSS 0.90%9.8CVE-2026-76461Cisco AsyncOS email parsing SQL injection allows root command executionCisco AsyncOS Software for Cisco Secure Email Gateway fails to properly validate email parsing input, allowing crafted email messages containing mali…KEVEPSS 28%analysed10.0CVE-2026-72898Metabase unauthenticated SQL injection in reset_password endpointMetabase exposes a database endpoint, '/reset_password', that fails to neutralize attacker-supplied SQL, allowing arbitrary SQL injection. Because th…KEVEPSS 19%analysed5.9CVE-2026-60137WordPress WP_Query author__not_in SQL injectionWordPress core fails to properly sanitise the author__not_in parameter of WP_Query in versions before 6.8.6, 6.9.5 and 7.0.2, allowing SQL injection …KEVEPSS 5.9%analysed9.8CVE-2026-9082Drupal core SQL injection in unauthenticated request pathDrupal core contains a SQL injection flaw (CWE-89) caused by improper neutralization of special elements in SQL commands. It affects multiple core br…KEVEPSS 16%analysed9.3CVE-2026-42208LiteLLM proxy SQL injection in API key checkLiteLLM versions 1.81.16 to before 1.83.7 build a database query for proxy API key checks by concatenating the caller-supplied key into the query tex…KEVEPSS 5.8%analysed9.8CVE-2026-21643FortiClientEMS SQL injection allows unauthenticated remote code executionFortiClientEMS 7.4.4 fails to neutralize special elements in SQL commands, exposing a SQL injection reachable through crafted HTTP requests. Because …KEVEPSS 94%analysed9.8CVE-2024-43468Microsoft Configuration Manager SQL injection enables remote code executionCVE-2024-43468 is a SQL injection flaw (CWE-89) in Microsoft Configuration Manager that leads to remote code execution. It carries a CVSS 3.1 score o…KEVEPSS 81%analysed

Source: NIST National Vulnerability Database (record CVE-2026-9586), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.