← Terug naar overzicht

Sangoma Switchvox contains a critical SQL injection vulnerability (CVE-2026-9586) that allows unauthenticated remote attackers to execute arbitrary SQL statements against the backend PostgreSQL database. Exploitation requires only a single crafted request, enabling database manipulation and remote code execution. The vulnerability is unauthenticated, significantly raising its severity and risk profile. CISA has listed this vulnerability under BOD 26-04, mandating prioritized patching for federal agencies. A patch is available in Switchvox version 8.4.0.2, released July 14, 2026. Organizations using Sangoma Switchvox should apply the update immediately. CISA also requires forensic triage for affected systems per BOD 26-04 implementation guidance.

Affected products

  • Sangoma Switchvox

Related CVE's

  • CVE-2026-9586

Categories

  • Database & Storage
  • Enterprise Applications
  • Network Infrastructure
  • Zero-Day Vulnerabilities