DIRAS TAKE
Treat this as urgent: CISA added this vulnerability to its Known Exploited Vulnerabilities catalog with a rapid mitigation due date, and public exploit code is available—apply vendor fixes or mitigations immediately for exposed systems.
What is CVE-2026-9586?
Unauthenticated attackers can send a single crafted request to Sangoma Switchvox and execute arbitrary SQL against its PostgreSQL backend, potentially leading to data compromise and remote code execution (CVE-2026-9586). The issue affects Switchvox 8.3 (104997) through versions before 8.4.0.2; a single unauthenticated network request to the /pa endpoint that supplies a manipulated PhoneIP value is sufficient to trigger the flaw. The weakness is classified as CWE-89 (SQL Injection).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Sangoma Switchvox are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 8.x | 8.3 (104997) – before 8.4.0.2 | 8.4.0.2 |
Is CVE-2026-9586 being exploited?
CISA added this vulnerability to the Known Exploited Vulnerabilities catalog on 2026-09-02, and U.S. federal agencies must remediate it by 2026-09-05; public exploit code is also available.
How to fix CVE-2026-9586
- Upgrade Switchvox to 8.4.0.2 (the vendor-provided fixed version).
- If you cannot upgrade immediately, restrict network exposure of Switchvox’s management and /pa endpoint to trusted hosts only.
- Apply any vendor-recommended mitigations and configuration changes from Sangoma guidance.
- Monitor Switchvox logs and PostgreSQL activity for suspicious queries and indicators of compromise.
Frequently asked questions
Is CVE-2026-9586 being actively exploited?
CISA added CVE-2026-9586 to its Known Exploited Vulnerabilities catalog on 2026-09-02 and set a remediation due date of 2026-09-05; public exploit code is also available.
Which Switchvox versions are affected by CVE-2026-9586?
Switchvox versions 8.3 (104997) through releases before 8.4.0.2 are affected.
Is there a patch for CVE-2026-9586?
Yes; Sangoma lists 8.4.0.2 as the fixed version for Switchvox.
Does CVE-2026-9586 require authentication?
No; the SQL injection in Switchvox is exploitable without authentication via a crafted request to the /pa endpoint.
References
- nvd.nist.gov/vuln/detail/CVE-2026-9586
- cve.org/CVERecord?id=CVE-2026-9586
- cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-9586
- sangomakb.atlassian.net/wiki/spaces/Switchvox/pages/1802371073/Switchvox+-+Release+Notes+Version+8.4.0.2+July+14+2026
- labs.sra.io/posts/switchvox
- All Sangoma CVEs on CVE Radar
- CVEs published in September 2026