← Back to CVE List
Vulnerability Intelligence Report
Authenticated Stored Cross-Site Scripting (XSS) in Switchvox SMB Web Portal

CVE-2026-9588

A stored cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997) within the voicemail notification template functionality. The submit_modify_voicemail_template endpoint fails to properly sanitize HTML content supplied by authenticated users, allowing malicious JavaScript supplied through the template_text parameter to be stored server-side and subsequently rendered to other users.

Cross-Site Scripting (XSS) No Active Exploit Signals
CVSS Base Score
7.0
HIGH
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-79 ↗CWE-79 Improper neutralization of input during web page generation ('cross-site scripting')

Affected Products & Versions

Vendor Product Affected Versions
Sangoma Switchvox SMB Edition 8.3 (104997) < 8.4.0.2 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

Vulnerability Class
Cross-Site Scripting (XSS)

Identity & Timeline

StatusPUBLISHED
Assigning AuthoritySecurity Risk Advisors (SRA) · Researcher · USA
Reserved2026-05-26T13:03:32
Published2026-07-17T15:59:23
Last Updated2026-07-17T16:42:08

LINK COPIED TO CLIPBOARD