· via dev.to (home feed)
Unauthenticated SQL injection in Sangoma Switchvox added to CISA's exploited-vulnerabilities catalog
A crafted provisioning request to Sangoma Switchvox's /pa endpoint can run arbitrary SQL, and potentially code, on unpatched systems. CISA listed CVE-2026-9586 as actively exploited with a 5 September patch deadline.

CISA has added CVE-2026-9586, an unauthenticated SQL injection in Sangoma's Switchvox business phone system, to its Known Exploited Vulnerabilities catalog. According to a dev.to write-up, the listing was made on 2 September 2026 with a remediation deadline of 5 September, and NVD gives the flaw a CVSS 3.1 base score of 9.8 with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H — network-reachable, no privileges required, no user interaction.
How the injection works
Switchvox provisions desk handsets over the network, and the endpoint that handles that traffic accepts XML submitted by devices, meaning it sits in front of whatever a caller chooses to send. In Switchvox SMB Edition 8.3 (build 104997), the /pa endpoint processes XML documents that begin with PolycomIPPhone. One field in that document, PhoneIP, is attacker-controlled, and according to the dev.to analysis the server pastes its value directly into PostgreSQL queries rather than parameterizing or sanitizing it. A single crafted request from an unauthenticated remote attacker is enough to run arbitrary SQL against the backend database. NVD's record, as relayed in the write-up, notes that the injected statements can extend to database operations and remote code execution.
What the database holds
That backend stores extension listings, call records and administrative accounts. A PBX is also rarely an isolated appliance: Switchvox deployments commonly tie into directory services, CRM systems, call-recording storage and alerting channels such as email and SMS gateways, all reachable in principle from database-level access. Because the attack needs no authentication, network reachability of /pa is the only precondition — and phone systems have a habit of outliving their documentation, leaving provisioning ports exposed on network segments nobody remembers opening.
The patch gap
Sangoma shipped a fix in July 2026 with release 8.4.0.2, roughly two months before the KEV listing. Public research on the flaw, including work from SRA Labs and Horizon3.ai cited by the write-up, walks through the exploitation path. That interval is the practical problem: organizations that track PBX software less rigorously than their servers could have spent the entire period exposed, unaware that a fix even existed.
What operators should do
Upgrade to Switchvox 8.4.0.2 or later, and verify the build actually running on the appliance — asset records for telephony gear tend to list the version shipped at purchase rather than what is installed today.
Restrict access to /pa. A device-provisioning endpoint rarely needs to be reachable from the wider corporate LAN, let alone the public internet; segmenting the phone VLAN so that only genuine handsets can connect eliminates the unauthenticated attack path.
Investigate the pre-patch window at the database level. Comb query logs for statements no normal application flow would produce, unexpected schema changes, newly created database users, and reads against tables the application never touches directly. Because code execution rides the same path, hunt for file-write and command-execution traces as well.
Rotate the credentials used for integrations and for database administration if compromise cannot be ruled out, and review call routing rules for unauthorized edits — on telephony platforms such rules persist across service restarts, which makes them a convenient place for an intruder to plant persistence.
Why it matters
This is a textbook case of appliance-style infrastructure escaping normal security discipline. A phone system accepts unauthenticated device input on the network, forwards part of it to a PostgreSQL backend, and holds enterprise data plus links to CRM, directory and messaging systems, yet it is often managed like office equipment rather than a server. The KEV listing means the flaw is being exploited in the wild, and the three days between the 2 September listing and the 5 September deadline signal urgency. Any organization running an affected Switchvox build should treat /pa as a live incident surface now, and take single-field injection bugs in appliances as a reminder that parameterization matters everywhere a query is built.
- #security
- #sql-injection
- #cve
- #voip
- #sangoma