SQL Injection Vulnerability in Sangoma Switchvox SMB Edition
CVE-2026-9586

9.3CRITICAL

Key Information:

Vendor

Sangoma

Vendor
CVE Published:
17 July 2026

Badges

🔥 Trending now📈 Trended📈 Score: 2,070👾 Exploit Exists🟡 Public PoC🟣 EPSS 11%🦅 CISA Reported📰 News Worthy

What is CVE-2026-9586?

CVE-2026-9586 is a critical vulnerability identified in the Sangoma Switchvox SMB Edition, specifically affecting version 8.3 (104997). Sangoma Switchvox is a comprehensive unified communications solution designed for small to medium-sized businesses, providing features such as VoIP, video conferencing, and collaboration tools. The vulnerability itself is categorized as an unauthenticated SQL injection, which occurs at the /pa endpoint that processes XML content, specifically beginning with . The major flaw arises from the direct integration of user-controlled input into PostgreSQL queries without adequate sanitization or parameterization, enabling an attacker to craft requests that can execute arbitrary SQL commands against the backend database. This could lead to severe repercussions, including potential remote code execution, thereby compromising organizational data integrity, user privacy, and system functionality.

Potential impact of CVE-2026-9586

  1. Unauthorized Database Access: Exploiting this vulnerability enables unauthenticated remote attackers to execute malicious SQL statements directly on the database. This can result in unauthorized access to sensitive data, unauthorized modifications, and potential data breaches.

  2. Remote Code Execution: Attackers could leverage the SQL injection to execute arbitrary code on the database server. This capability can lead to an escalation of privileges and may grant the attacker full control over the vulnerable system, allowing for further exploitation of the network environment.

  3. Disruption of Business Operations: By compromising the backend database and possibly taking control of the communication system, the exploitation of this vulnerability could severely disrupt business operations. Organizations may face downtime, loss of productivity, and damaged reputation as customers lose trust in the security of their communications infrastructure.

CISA has reported CVE-2026-9586

CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2026-9586 as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace

The CISA's recommendation is: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Affected Version(s)

Switchvox SMB Edition 8.3 (104997) < 8.4.0.2

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

News Articles

Week in review: Claude accounts compromised through infostealer, Patch Tuesday forecast - Help Net Security

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Anthropic locks out Claude users after infostealers

2 days ago

Switchvox Vulnerability Triggers Active Exploitation Risk - IT Security News

2026-09-05 19:09 Sangoma Switchvox CVE-2026-9586 is a serious unauthenticated SQL injection flaw that can lead to remote code execution, and Horizon3 says it has already seen real-world...

2 days ago

Sangoma Switchvox Vulnerabilities Exploited in the Wild

Hackers have been exploiting a critical-severity vulnerability (CVE-2026-9586) in the enterprise VoIP telephony management solution Sangoma Switchvox.

4 days ago

References

EPSS Score

11% chance of being exploited in the next 30 days.

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • 📈

    Vulnerability started trending

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • 🦅

    CISA Reported

  • 📰

    First article discovered by The Hacker News

  • Vulnerability published

  • Vulnerability Reserved

Credit

Cam Lischke (SRA)
.