SQL Injection Vulnerability in Sangoma Switchvox
Sangoma Switchvox is vulnerable to an unauthenticated SQL injection flaw that allows remote attackers to execute arbitrary SQL commands on the backend PostgreSQL database, potentially leading to remote code execution.
CVE search metadata
CVE search record: CVE-2026-9586. EPSS: 0.69%. KEV: no. Product: Switchvox (< 8.4.0.2). Brief: SQL Injection Vulnerability in Sangoma Switchvox. Brief link: https://feed.craftedsignal.io/briefs/2026-09-sangoma-switchvox-sqli/
Sangoma Switchvox versions prior to 8.4.0.2 are affected by a critical SQL injection vulnerability (CVE-2026-9586). This flaw enables an unauthenticated, remote attacker to interact with the backend PostgreSQL database by sending a single, specifically crafted HTTP request to the appliance. Successful exploitation grants the attacker the ability to execute arbitrary SQL statements. Depending on the database configuration and permissions, this capability may be leveraged to manipulate sensitive data or achieve remote code execution on the underlying appliance, which is typically used for telecommunications and VoIP services. Given the nature of these appliances, they are often internet-facing, increasing the risk of widespread automated scanning and exploitation. Organizations utilizing Switchvox must prioritize upgrading to version 8.4.0.2 or later in accordance with CISA Binding Operational Directive 26-04.
Impact
Successful exploitation of this vulnerability allows unauthenticated attackers to gain unauthorized access to the backend database of affected Sangoma Switchvox appliances. This can result in the full compromise of the device, data exfiltration, service disruption, or the potential for lateral movement within the network where the appliance is deployed. As a critical vulnerability listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, it poses an immediate risk to any enterprise-grade deployment.
Recommendation
- Immediately upgrade all Sangoma Switchvox instances to version 8.4.0.2 or later to remediate CVE-2026-9586.
- Evaluate the internet exposure of all Switchvox appliances and apply access control lists (ACLs) to restrict access to management interfaces to trusted IP addresses only.
- Adhere to CISA BOD 26-04 guidelines for prioritizing security updates and perform forensics triage on any appliances that show signs of unauthorized access or anomalous activity.
Immediate actions
Upgrade all internet-facing Switchvox instances to version 8.4.0.2.
Mitigations
Restrict management interface access to internal/trusted IP ranges via firewall rules.
CVE-2026-9586