Skip to main content
UNKNOWN CISA KEV

CVE-2026-9586

Unauthenticated SQL Injection Leading to Remote Code Execution in Switchvox SMB

CVSS v3

Unknown

EPSS Score

0.4 %

exploit probability

CISA KEV

Yes

known exploited

Exploitation

none

SSVC status

Description

An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates the user-controlled PhoneIP value into PostgreSQL queries without sanitization or parameterization. An unauthenticated remote attacker can execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.

CISA Known Exploited Vulnerability

Date Added
2026-09-02
Patch Due Date
2026-09-05
Ransomware Use
Unknown

Technical details

Published
2026-07-17
Last Modified
2026-07-17

Frequently asked questions

What is CVE-2026-9586?

An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates the user-controlled PhoneIP value into PostgreSQL queries without sanitization or parameterization. An unauthenticated remote attacker can execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.

Is CVE-2026-9586 actively exploited?

Yes. CVE-2026-9586 is on the CISA Known Exploited Vulnerabilities (KEV) catalog, meaning it has been confirmed as actively exploited in the wild. CISA requires federal agencies to patch by 2026-09-05.

What is the CVSS score for CVE-2026-9586?

A CVSS score has not been assigned to CVE-2026-9586 yet.

Is CVE-2026-9586 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key