CVE-2026-9586
NONE—CVSS v3
—CVSS v2
0.41%
EPSS (exploit probability)
CWE-89CWE
Description
An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates the user-controlled PhoneIP value into PostgreSQL queries without sanitization or parameterization. An unauthenticated remote attacker can execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.
Affected routers (0)
No routers currently mapped to this CVE in our database.