CVE-2026-9586
An unauthenticated SQL injection flaw in Sangoma Switchvox SMB Edition 8.3 (104997) allows remote attackers to inject arbitrary SQL via the PhoneIP field in XML sent to the /pa endpoint. Because the input is directly concatenated into PostgreSQL queries without sanitization, an attacker can read, modify, or delete data and potentially achieve remote code execution. The vulnerability carries a CVSS v4.0 base score of 9.3 (Critical).
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Sangoma Switchvox SMB Edition 8.3 (104997)
Real-world impact
An unauthenticated remote attacker can execute arbitrary SQL statements against the backend PostgreSQL database, leading to data theft, manipulation, or remote code execution.
Why this severity
CVSS v4.0 base score of 9.3 (Critical) reflects the combination of network‑adjacent attack vector, low attack complexity, no privileges or user interaction required, and high impacts to confidentiality, integrity, and availability.
What to do about it
- 01No official fix is available in the provided sources.
- ›Restrict network access to the /pa endpoint to trusted hosts.
- ›Monitor and block suspicious XML payloads containing unexpected PhoneIP values.
Mitigation suggestions are generic best‑practice guidance; no vendor‑specific remediation is documented in the source data.