Skip to content
Threat Feed
critical advisory

SQL Injection Vulnerability in Sangoma Switchvox

Sangoma Switchvox is vulnerable to an unauthenticated SQL injection flaw that allows remote attackers to execute arbitrary SQL commands on the backend PostgreSQL database, potentially leading to remote code execution.

CVE search metadata

CVE search record: CVE-2026-9586. EPSS: 0.69%. KEV: no. Product: Switchvox (< 8.4.0.2). Brief: SQL Injection Vulnerability in Sangoma Switchvox. Brief link: https://feed.craftedsignal.io/briefs/2026-09-sangoma-switchvox-sqli/

Sangoma Switchvox versions prior to 8.4.0.2 are affected by a critical SQL injection vulnerability (CVE-2026-9586). This flaw enables an unauthenticated, remote attacker to interact with the backend PostgreSQL database by sending a single, specifically crafted HTTP request to the appliance. Successful exploitation grants the attacker the ability to execute arbitrary SQL statements. Depending on the database configuration and permissions, this capability may be leveraged to manipulate sensitive data or achieve remote code execution on the underlying appliance, which is typically used for telecommunications and VoIP services. Given the nature of these appliances, they are often internet-facing, increasing the risk of widespread automated scanning and exploitation. Organizations utilizing Switchvox must prioritize upgrading to version 8.4.0.2 or later in accordance with CISA Binding Operational Directive 26-04.

Impact

Successful exploitation of this vulnerability allows unauthenticated attackers to gain unauthorized access to the backend database of affected Sangoma Switchvox appliances. This can result in the full compromise of the device, data exfiltration, service disruption, or the potential for lateral movement within the network where the appliance is deployed. As a critical vulnerability listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, it poses an immediate risk to any enterprise-grade deployment.

Recommendation

  • Immediately upgrade all Sangoma Switchvox instances to version 8.4.0.2 or later to remediate CVE-2026-9586.
  • Evaluate the internet exposure of all Switchvox appliances and apply access control lists (ACLs) to restrict access to management interfaces to trusted IP addresses only.
  • Adhere to CISA BOD 26-04 guidelines for prioritizing security updates and perform forensics triage on any appliances that show signs of unauthorized access or anomalous activity.

Immediate actions

Upgrade all internet-facing Switchvox instances to version 8.4.0.2.

IT Operations 2026-09-05

Mitigations

Restrict management interface access to internal/trusted IP ranges via firewall rules.

immediate Network Security

CVE-2026-9586