Critical Unauthenticated SQL Injection in Sangoma Switchvox Enables RCE
CVE-2026-9586 is a critical unauthenticated SQL injection vulnerability within the Asterisk-based VoIP engine used in Sangoma Switchvox SMB Edition 8.3 (Build 104997). By submitting specially crafted XML requests, remote attackers can bypass authentication and execute malicious SQL commands. This vulnerability enables an exploitation chain leading to operating system command injection and Remote Code Execution (RCE). Such access allows attackers to deploy persistent reverse shells, facilitating full system control and potential interception of VoIP traffic. Currently, this vulnerability is being actively exploited in the wild against internet-exposed Switchvox instances, posing an immediate risk to small and medium-sized business communications infrastructure.