• CISA KEV
  • EXPLOITED
  • PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-9586: unauthenticated sql injection in Sangoma Switchvox

Unauthenticated attackers can send a single crafted request to Sangoma Switchvox and execute arbitrary SQL against its PostgreSQL backend, potentially leading to data compromise and remote code execution (CVE-2026-9586). The issue affects Switchvox 8.3 (104997) through versions before 8.4.0.2; a single unauthenticated network request to the /pa endpoint that supplies a manipulated PhoneIP value is sufficient to trigger the flaw.

Published Updated Source: CVE Program, NVD, CISA KEV, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.18979
CWE
CWE-89
KEV DUE DATE
PATCH
Available

DIRAS TAKE

Treat this as urgent: CISA added this vulnerability to its Known Exploited Vulnerabilities catalog with a rapid mitigation due date, and public exploit code is available—apply vendor fixes or mitigations immediately for exposed systems.

What is CVE-2026-9586?

Unauthenticated attackers can send a single crafted request to Sangoma Switchvox and execute arbitrary SQL against its PostgreSQL backend, potentially leading to data compromise and remote code execution (CVE-2026-9586). The issue affects Switchvox 8.3 (104997) through versions before 8.4.0.2; a single unauthenticated network request to the /pa endpoint that supplies a manipulated PhoneIP value is sufficient to trigger the flaw. The weakness is classified as CWE-89 (SQL Injection).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Sangoma Switchvox are affected?

BRANCHAFFECTEDFIXED
8.x8.3 (104997) – before 8.4.0.28.4.0.2

Is CVE-2026-9586 being exploited?

CISA added this vulnerability to the Known Exploited Vulnerabilities catalog on 2026-09-02, and U.S. federal agencies must remediate it by 2026-09-05; public exploit code is also available.

How to fix CVE-2026-9586

  1. Upgrade Switchvox to 8.4.0.2 (the vendor-provided fixed version).
  2. If you cannot upgrade immediately, restrict network exposure of Switchvox’s management and /pa endpoint to trusted hosts only.
  3. Apply any vendor-recommended mitigations and configuration changes from Sangoma guidance.
  4. Monitor Switchvox logs and PostgreSQL activity for suspicious queries and indicators of compromise.

Frequently asked questions

Is CVE-2026-9586 being actively exploited?

CISA added CVE-2026-9586 to its Known Exploited Vulnerabilities catalog on 2026-09-02 and set a remediation due date of 2026-09-05; public exploit code is also available.

Which Switchvox versions are affected by CVE-2026-9586?

Switchvox versions 8.3 (104997) through releases before 8.4.0.2 are affected.

Is there a patch for CVE-2026-9586?

Yes; Sangoma lists 8.4.0.2 as the fixed version for Switchvox.

Does CVE-2026-9586 require authentication?

No; the SQL injection in Switchvox is exploitable without authentication via a crafted request to the /pa endpoint.

References