CVE-2026-9586: One XML Field in Sangoma Switchvox Reaches the PostgreSQL Backend
CVE-2026-9586: One XML Field in Sangoma Switchvox Reaches the PostgreSQL Backend A phone provisioning endpoint that trusts what it is told Sangoma Switchvox is a business phone system that provisions desk handsets over the network. The endpoint that handles that provisioning accepts XML from devices, which places it in front of anything the caller chooses to send. CVE-2026-9586 is a SQL injection…
CVE-2026-9586 is a SQL injection vulnerability affecting a phone provisioning endpoint in Sangoma Switchvox, a business phone system. The endpoint, which trusts the data it receives, accepts XML input from devices and processes it without proper sanitization or parameterization. This allows an unauthenticated remote attacker to craft a single request that can execute arbitrary SQL statements against the PostgreSQL backend database.
The vulnerability, which was added to the Known Exploited Vulnerabilities catalog by CISA on 2 September 2026, has a high CVSS 3.1 base score of 9.8, indicating it can lead to database operations and remote code execution. Organizations using Switchvox SMB Edition 8.3 (104997) are at risk of having their database compromised, which could grant attackers access to sensitive information such as extensions, call records, and administrative accounts.
The issue arises because the /pa endpoint processes XML content beginning with PolycomIPPhone and directly concatenates the user-controlled PhoneIP value into PostgreSQL queries without proper sanitization. This flaw was fixed in Switchvox 8.4.0.2, released in July 2026, but organizations using older versions who do not track software updates may still be exposed.
Remediation involves upgrading to a patched version, restricting access to the provisioning endpoint, segmenting the phone VLAN to prevent unauthorized access, and investigating for any signs of exploitation in the database logs.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.