Vulnary
← back to the feed
Critical· 9.3

CVE-2026-9586

An unauthenticated SQL injection flaw in Sangoma Switchvox SMB Edition 8.3 (104997) allows remote attackers to inject arbitrary SQL via the PhoneIP field in XML sent to the /pa endpoint. Because the input is directly concatenated into PostgreSQL queries without sanitization, an attacker can read, modify, or delete data and potentially achieve remote code execution. The vulnerability carries a CVSS v4.0 base score of 9.3 (Critical).

publishedJul 17, 2026
last modifiedJul 17, 2026
sourcesNVD
severity · cvss
9.3
critical · how bad it is
exploitation · epss
<1%
34th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Sep 1, 2026

No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.

01

Who is affected

Sangoma Switchvox SMB Edition 8.3 (104997)

02

Real-world impact

An unauthenticated remote attacker can execute arbitrary SQL statements against the backend PostgreSQL database, leading to data theft, manipulation, or remote code execution.

03

Why this severity

CVSS v4.0 base score of 9.3 (Critical) reflects the combination of network‑adjacent attack vector, low attack complexity, no privileges or user interaction required, and high impacts to confidentiality, integrity, and availability.

04

What to do about it

no official fix yet
recommended steps
  1. 01No official fix is available in the provided sources.
interim mitigations
  • Restrict network access to the /pa endpoint to trusted hosts.
  • Monitor and block suspicious XML payloads containing unexpected PhoneIP values.

Mitigation suggestions are generic best‑practice guidance; no vendor‑specific remediation is documented in the source data.

05

Timeline

06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityLow
Attack requirementsNone
Privileges requiredNone
User interactionNone needed
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →