S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Sep 2, 2026

CVE-2026-9586 Scanner

CVE-2026-9586 Scanner - SQL Injection vulnerability in Sangoma Switchvox

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsdomain, subdomain, ipv4
CostFree
3
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2026-9586
9.3
CVSScritical
Exploitable remotely over the internet · no authentication required.

An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates the user-controlled PhoneIP value into PostgreSQL queries without sanitization or parameterization. An unauthenticated remote attacker can execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Switchvox SMB Editionby Sangoma
AFFECTED< 8.4.0.2SAFE ✓≥ 8.4.0.2
Updated Sep 9, 2026View on NVD →
Detail

Sangoma Switchvox is widely used in enterprise environments to provide unified communications solutions. It integrates with existing infrastructure to offer voice, video, and messaging capabilities. Organizations often rely on it for its robust feature set and scalability. Switchvox can be used in both small and large organizations to streamline communication operations. It is designed to improve productivity by simplifying communication workflows and has broad appeal due to its flexibility and reliability. Critical to its adoption is the assurance of secure operations, which is why identifying vulnerabilities is crucial.

The SQL Injection vulnerability in Sangoma Switchvox is particularly severe due to its potential to compromise the entire system. It allows an unauthenticated attacker to execute arbitrary commands on the server by injecting malicious SQL code. The vulnerability exists in the /pa endpoint, specifically the PhoneIP field in an XML POST request which is directly used in SQL queries without proper validation. The ability to execute operating system commands via the database server significantly raises the risk profile of this vulnerability. Addressing this issue promptly is vital to maintaining system integrity.

The vulnerability hinges upon improper handling of input data in a key communication component of Switchvox. The PhoneIP field in incoming requests is concatenated without sufficient sanitization, allowing attackers to manipulate SQL queries. This oversight in validation permits a breakout from the SQL string context, enabling not just data manipulation but also command injection via PostgreSQL's COPY TO PROGRAM capability. This technical flaw can lead to complete system takeover if exploited, highlighting the importance of securely coding input handling functions.

Exploitation of this SQL Injection vulnerability can lead to severe consequences, including unauthorized access and control over the affected system. Attackers can execute arbitrary system commands, potentially exfiltrating sensitive data or disrupting services. Additionally, such a vulnerability provides a gateway for further attacks, potentially exploiting additional system weaknesses or pivoting to other parts of the network. The impact is compounded by the fact that no authentication is needed, lowering the barrier for would-be attackers.

REFERENCES

Solution Advice
  • Upgrade to Sangoma Switchvox version 8.4.0.2 or later to fix the SQL injection issue by parameterizing queries.
  • Implement input validation to ensure that fields received in requests do not contain untrusted data.
  • Deploy web application firewalls (WAFs) to detect and block malicious requests targeting vulnerable endpoints.
  • Regularly review and test the security of application endpoints to identify potential vulnerabilities early.
  • Ensure server access is restricted and monitored to detect unauthorized attempts swiftly.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.