CVE-2026-9586: SQL injection in Sangoma Switchvox rated 9.8
Sangoma Switchvox SMB Edition 8.3 contains CVE-2026-9586, a CVSS 9.8 SQL injection: an unauthenticated attacker can inject SQL through the PhoneIP XML field on the /pa provisioning endpoint, with remote code execution reachable from the same path. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2 September 2026; the fix shipped in version 8.4.0.2 in July.
- CVSS 3.1 base score 9.8, no authentication or user interaction required
- Vulnerable endpoint /pa in Switchvox SMB Edition 8.3 (104997)
- Fixed in Switchvox 8.4.0.2, released 14 July 2026
- CISA added the CVE to its KEV catalog on 2 September 2026
Read next
Security