Vulnerability Intelligence Report
Unauthenticated SQL Injection Leading to Remote Code Execution in Switchvox SMB
CVE-2026-9586
An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates the user-controlled PhoneIP value into PostgreSQL queries without sanitization or parameterization. An unauthenticated remote attacker can execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.
CISA KEV
Nuclei Template
SSVC: Active Exploitation
Automatable
Injection
CVSS Base Score
9.3
CRITICAL
EPSS Probability:1.09%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-89 ↗CWE-89 Improper neutralization of special elements used in an SQL command ('SQL injection')
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Sangoma | Switchvox SMB Edition | 8.3 (104997) < 8.4.0.2 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
CISA KEV
ACTIVE IN CATALOG
Nuclei Template
SCANNER AVAILABLE
EPSS Score
1.088%
GitHub Advisory
Vulnerability Class
Injection
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Security Risk Advisors (SRA) · Researcher · USA |
| Reserved | 2026-05-26T13:03:30 |
| Published | 2026-07-17T15:57:42 |
| Last Updated | 2026-09-03T03:55:29 |
Community Chatter & Buzz