CVE-2026-9586
An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates the user-controlled PhoneIP value into PostgreSQL queries without sanitization or parameterization. An unauthenticated remote attacker can execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.
Alerte précoce : exploitation observée
- Exploitation observée depuis le 1 sept. 2026
- Pas encore dans le catalogue officiel de la CISA
- Première attaque observée 45 jours après la divulgation
Source : VulnCheck KEV · 1 sept. 2026 1 sept. 2026 1 sept. 2026 1 sept. 2026
Type de faiblesse (CWE)CWE-89
Articles liés
This product uses the NVD API but is not endorsed or certified by the NVD.
