Vulnerabilities
Vulnerable Software
Sangoma:  >> Switchvox  >> 8.4  Security Vulnerabilities
CVE-2026-9586
Known exploited
An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates the user-controlled PhoneIP value into PostgreSQL queries without sanitization or parameterization. An unauthenticated remote attacker can execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.
CVSS Score
9.3
EPSS Score
0.118
Published
2026-07-17


Contact Us

Shodan ® - All rights reserved