{
  "id": 10829929,
  "title": "CVE-2026-9586: One XML Field in Sangoma Switchvox Reaches the PostgreSQL Backend",
  "url": "https://urgent.news/2026/09/30/cve-2026-9586-one-xml-field-in-sangoma-switchvox-reaches-the",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-30T02:00:19.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/jeffreyciend/cve-2026-9586-one-xml-field-in-sangoma-switchvox-reaches-the-postgresql-backend-o45"
  },
  "original_language": "en",
  "account": "CVE-2026-9586 is a SQL injection vulnerability affecting a phone provisioning endpoint in Sangoma Switchvox, a business phone system. The endpoint, which trusts the data it receives, accepts XML input from devices and processes it without proper sanitization or parameterization. This allows an unauthenticated remote attacker to craft a single request that can execute arbitrary SQL statements against the PostgreSQL backend database. The vulnerability, which was added to the Known Exploited Vulnerabilities catalog by CISA on 2 September 2026, has a high CVSS 3.1 base score of 9.8, indicating it can lead to database operations and remote code execution. Organizations using Switchvox SMB Edition 8.3 (104997) are at risk of having their database compromised, which could grant attackers access to sensitive information such as extensions, call records, and administrative accounts. The issue arises because the /pa endpoint processes XML content beginning with PolycomIPPhone and directly concatenates the user-controlled PhoneIP value into PostgreSQL queries without proper sanitization. This flaw was fixed in Switchvox 8.4.0.2, released in July 2026, but organizations using older versions who do not track software updates may still be exposed. Remediation involves upgrading to a patched version, restricting access to the provisioning endpoint, segmenting the phone VLAN to prevent unauthorized access, and investigating for any signs of exploitation in the database logs.",
  "summary": "CVE-2026-9586: One XML Field in Sangoma Switchvox Reaches the PostgreSQL Backend A phone provisioning endpoint that trusts what it is told Sangoma Switchvox is a business phone system that provisions desk handsets over the network. The endpoint that handles that provisioning accepts XML from devices, which places it in front of anything the caller chooses to send. CVE-2026-9586 is a SQL injection…",
  "key_points": [
    "Sangoma Switchvox phone system vulnerable to SQL injection.",
    "Unauthenticated attacker can execute arbitrary SQL statements.",
    "Fixed in Switchvox 8.4.0.2, released July 2026."
  ],
  "editors_take": "This vulnerability allows unauthenticated remote attackers to execute arbitrary SQL statements, potentially granting access to sensitive information, until patched versions are implemented and access is restricted.",
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}