---
id: CVE-2026-9586
title: "An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997).\_The /pa endpoint processes XML\_content beginning with <PolycomIPPhone> and\_directly concatenates the user-controlled PhoneIP value into …"
summary: "An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997).\_The /pa endpoint processes XML\_content beginning with <PolycomIPPhone> and\_directly concatenates the user-controlled PhoneIP value into …"
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-89
vendor: sangoma
product: switchvox
affected:
  - 'switchvox >= 8.2.2.1, < 8.4.0.2'
patched:
  - switchvox 8.4.0.2
published: '2026-07-17'
updated: '2026-09-03'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-9586'
references:
  - url: 'https://labs.sra.io/posts/switchvox/'
    label: 57dba5dd-1a03-47f6-8b36-e84e47d335d8
  - url: >-
      https://sangomakb.atlassian.net/wiki/spaces/Switchvox/pages/1802371073/Switchvox+-+Release+Notes+Version+8.4.0.2+July+14+2026
    label: 57dba5dd-1a03-47f6-8b36-e84e47d335d8
  - url: >-
      https://horizon3.ai/attack-research/disclosures/cve-2026-9586-sangoma-switchvox-rce/#
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-9586
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - kev
  - in-the-wild
  - exploit-available
epss: 0.11845
epssPercentile: 0.95902
kev: true
kevDateAdded: '2026-09-02'
kevDueDate: '2026-09-05'
kevRansomware: false
exploited: true
ingestedAt: '2026-09-04T04:14:25.390Z'
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/HORKimhab/CVE-2026-9586'
  nuclei:
    - CVE-2026-9586
  checkedAt: '2026-09-23T07:15:25.298Z'
exploitAvailable: true
---

## Overview

An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates the user-controlled PhoneIP value into PostgreSQL queries without sanitization or parameterization. An unauthenticated remote attacker can execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.

## Affected

- `switchvox >= 8.2.2.1, < 8.4.0.2`

## Remediation

Upgrade past the affected range:

- `switchvox 8.4.0.2`
