Urgent.News

What's breaking now, across thousands of outlets.

Tech

CVE-2026-9586: One XML Field in Sangoma Switchvox Reaches the PostgreSQL Backend

CVE-2026-9586: One XML Field in Sangoma Switchvox Reaches the PostgreSQL Backend A phone provisioning endpoint that trusts what it is told Sangoma Switchvox is a business phone system that provisions desk handsets over the network. The endpoint that handles that provisioning accepts XML from devices, which places it in front of anything the caller chooses to send. CVE-2026-9586 is a SQL injection…

CVE-2026-9586 is a SQL injection vulnerability affecting a phone provisioning endpoint in Sangoma Switchvox, a business phone system. The endpoint, which trusts the data it receives, accepts XML input from devices and processes it without proper sanitization or parameterization. This allows an unauthenticated remote attacker to craft a single request that can execute arbitrary SQL statements against the PostgreSQL backend database.

The vulnerability, which was added to the Known Exploited Vulnerabilities catalog by CISA on 2 September 2026, has a high CVSS 3.1 base score of 9.8, indicating it can lead to database operations and remote code execution. Organizations using Switchvox SMB Edition 8.3 (104997) are at risk of having their database compromised, which could grant attackers access to sensitive information such as extensions, call records, and administrative accounts.

The issue arises because the /pa endpoint processes XML content beginning with PolycomIPPhone and directly concatenates the user-controlled PhoneIP value into PostgreSQL queries without proper sanitization. This flaw was fixed in Switchvox 8.4.0.2, released in July 2026, but organizations using older versions who do not track software updates may still be exposed.

Remediation involves upgrading to a patched version, restricting access to the provisioning endpoint, segmenting the phone VLAN to prevent unauthorized access, and investigating for any signs of exploitation in the database logs.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

소스 인식 검증(ProvenanceGuard)이 1인 개발자에게 의미하는 것

왜 소스 인식 검증이 중요한가 LLM 에이전트가 여러 검색·데이터베이스 도구를 호출해 답변을 만들면, "사실 여부"만 검증하는 기존 방법으로는 충분하지 않다. 답변이 어느 소스에서 온지를 잘못 연결하면, 의료 기록이나 고객 계정처럼 민감한 데이터에서 큰 위험이 된다.

  • ProvenanceGuard verifies information sources for LLM agents
  • Developed by Hugging Face to prevent risks with sensitive data
  • Requires five steps: claim division, source matching, support checking

Getting started with C# SOLID Principles

In my repo I've got this `using MusicLab.Projects.Models; using System.Collections.Generic; using System.Linq; namespace MusicLab.Projects.Data { public class InstrumentRepository…

  • The article explains SOLID principles in C# programming
  • Code demonstrates Single Responsibility, Interface Segregation, Dependency Inversion
  • Interfaces and dependency injection promote modularity and testability

Audit-readiness isn't a pre-audit sprint — three daily habits from a quality engineer's notebook

Auditor: "Show me training records for SOP-014, revision F." Me: "Sure." Me, twenty minutes later: "...this revision was effective eleven months ago and there's no re-attestation on file." That gap is…

  • Map Standard Operating Procedures (SOPs) as interconnected documents
  • Verify connections, not just map them, to prevent outdated references
  • Automate routine approvals while maintaining human accountability trail

More from Wednesday 30 September →