SQL Injection Vulnerability in Sangoma Switchvox SMB Edition
CVE-2026-9586
Key Information:
- Vendor
Sangoma
- Status
- Vendor
- CVE Published:
- 17 July 2026
Badges
What is CVE-2026-9586?
CVE-2026-9586 is a critical vulnerability identified in the Sangoma Switchvox SMB Edition, specifically affecting version 8.3 (104997). Sangoma Switchvox is a comprehensive unified communications solution designed for small to medium-sized businesses, providing features such as VoIP, video conferencing, and collaboration tools. The vulnerability itself is categorized as an unauthenticated SQL injection, which occurs at the /pa endpoint that processes XML content, specifically beginning with . The major flaw arises from the direct integration of user-controlled input into PostgreSQL queries without adequate sanitization or parameterization, enabling an attacker to craft requests that can execute arbitrary SQL commands against the backend database. This could lead to severe repercussions, including potential remote code execution, thereby compromising organizational data integrity, user privacy, and system functionality.
Potential impact of CVE-2026-9586
-
Unauthorized Database Access: Exploiting this vulnerability enables unauthenticated remote attackers to execute malicious SQL statements directly on the database. This can result in unauthorized access to sensitive data, unauthorized modifications, and potential data breaches.
-
Remote Code Execution: Attackers could leverage the SQL injection to execute arbitrary code on the database server. This capability can lead to an escalation of privileges and may grant the attacker full control over the vulnerable system, allowing for further exploitation of the network environment.
-
Disruption of Business Operations: By compromising the backend database and possibly taking control of the communication system, the exploitation of this vulnerability could severely disrupt business operations. Organizations may face downtime, loss of productivity, and damaged reputation as customers lose trust in the security of their communications infrastructure.
CISA has reported CVE-2026-9586
CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2026-9586 as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace
The CISA's recommendation is: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Affected Version(s)
Switchvox SMB Edition 8.3 (104997) < 8.4.0.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
News Articles
Week in review: Claude accounts compromised through infostealer, Patch Tuesday forecast - Help Net Security
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Anthropic locks out Claude users after infostealers
2 days ago
Switchvox Vulnerability Triggers Active Exploitation Risk - IT Security News
2026-09-05 19:09 Sangoma Switchvox CVE-2026-9586 is a serious unauthenticated SQL injection flaw that can lead to remote code execution, and Horizon3 says it has already seen real-world...
2 days ago
Sangoma Switchvox Vulnerabilities Exploited in the Wild
Hackers have been exploiting a critical-severity vulnerability (CVE-2026-9586) in the enterprise VoIP telephony management solution Sangoma Switchvox.
4 days ago
References
EPSS Score
11% chance of being exploited in the next 30 days.
CVSS V4
Timeline
- 📈
Vulnerability started trending
- 🟡
Public PoC available
- 👾
Exploit known to exist
- 🦅
CISA Reported
- 📰
First article discovered by The Hacker News
Vulnerability published
Vulnerability Reserved
