CVE-2026-9586 is a critical unauthenticated SQL injection vulnerability within the Asterisk-based VoIP engine used in Sangoma Switchvox SMB Edition 8.3 (Build 104997). By submitting specially crafted XML requests, remote attackers can bypass authentication and execute malicious SQL commands. This vulnerability enables an exploitation chain leading to operating system command injection and Remote Code Execution (RCE). Such access allows attackers to deploy persistent reverse shells, facilitating full system control and potential interception of VoIP traffic. Currently, this vulnerability is being actively exploited in the wild against internet-exposed Switchvox instances, posing an immediate risk to small and medium-sized business communications infrastructure.
- Vulnerability Overview: Technical Context
- Affected Software: Specifically impacts Sangoma Switchvox SMB Edition 8.3 (Build 104997).
- Underlying Architecture: The flaw resides in the Asterisk-based VoIP unified communications engine.
- Vulnerability Class: An unauthenticated SQL injection (SQLi) triggered during the processing of XML-formatted web requests.
- Exploitation Mechanics: Attack Vector
- Primary Vector: Threat actors utilize specially crafted XML payloads to bypass standard authentication mechanisms.
- Escalation Path: Malicious SQL injection facilitates a direct pivot to arbitrary operating system command execution.
- Payload Delivery: Successful exploitation enables the deployment of persistent reverse shells to maintain long-term access.
- Impact Assessment: Risk Profile
- Severity Rating: Classified as Critical with a CVSS score of 9.3.
- Current Threat Landscape: Confirmed active exploitation targeting internet-facing Switchvox deployments.
- Business Consequences: Full infrastructure compromise, unauthorized interception of VoIP communications, and potential lateral movement into internal SMB networks.
- Detection & Mitigation: Defensive Response
- Remediation Priority: Immediate deployment of vendor-provided security patches is mandatory for all affected versions.
- Network Monitoring: Audit for unusual outbound connections to external IP addresses, which may indicate active reverse shell establishment.
- Incident Investigation: Scrutinize system logs for unexpected command execution originating from the Switchvox service and analyze XML web request patterns for injection indicators.
Related posts
- xploitzone.com — CVE-2026-9586 Sangoma Switchvox SQL Injection Lets Hackers Deploy Reverse Shell
- horizon3.ai — Off the Hook: Discovering and Observing Active Exploitation of Sangoma Switchvox CVE-2026-9586
- feeds.feedburner.com — Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials
- helpnetsecurity.com — Exploitation of Sangoma Switchvox flaw is underway (CVE-2026-9586)
- SC Media — Critical SQL injection vulnerability in Sangoma Switchvox exploited in the wild
- bleepingcomputer.com — Hackers exploit Sangoma Switchvox flaw to deploy reverse shells
- Ionix
- Github
- Nvd