DEV Community

jeffrey
jeffrey

Posted on

CVE-2026-9586: One XML Field in Sangoma Switchvox Reaches the PostgreSQL Backend

CVE-2026-9586: One XML Field in Sangoma Switchvox Reaches the PostgreSQL Backend

A phone provisioning endpoint that trusts what it is told

Sangoma Switchvox is a business phone system that provisions desk handsets over the network. The endpoint that handles that provisioning accepts XML from devices, which places it in front of anything the caller chooses to send. CVE-2026-9586 is a SQL injection in that path.
CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2 September 2026 with a due date of 5 September. NVD records a CVSS 3.1 base score of 9.8 with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.

What the vulnerability is

In Switchvox SMB Edition 8.3 (104997), the /pa endpoint processes XML content beginning with PolycomIPPhone and concatenates the user-controlled PhoneIP value directly into PostgreSQL queries without sanitization or parameterization. An unauthenticated remote attacker can execute arbitrary SQL statements against the backend database with a single crafted request.
NVD notes that the injected statements can include database operations and remote code execution. The CISA description frames the same consequence in similar terms. An unauthenticated caller, one crafted request, and database level access to the system that stores extensions, call records and administrative accounts.

Why a phone system database is an enterprise target

A business phone system is not an isolated appliance. Switchvox integrations commonly include directory services, CRM systems, call recording storage and alerting platforms such as email and SMS gateways. Administrative access to its database can reach those connections.
Public research on this vulnerability walks through the exploitation path, and the vendor released a fixed version in July 2026. The gap between a July fix and a September KEV addition is the practical problem: organizations that do not track PBX software like they track servers carried the exposure for two months.
PBX systems also have a habit of outliving their documentation. A deployment that was installed for one office and later absorbed into a larger estate may still accept provisioning requests from segments nobody remembers opening. The unauthenticated requirement means reachability is the only precondition.

Remediation

Upgrade to Switchvox 8.4.0.2 or later. Confirm the running build on the appliance, since recorded versions for telecom systems frequently reflect the purchase date rather than the current state.
Restrict access to the provisioning endpoint. Hands-free XML endpoints rarely need to be reachable from the general corporate network, let alone from the internet. Segmenting the phone VLAN so only genuine handsets reach /pa removes the exposure for the unauthenticated case.
Investigate the pre-patch window at the database level. SQL injection leaves evidence in query logs, especially statements that do not correspond to normal application behavior. Look for schema changes, new database users, and reads from tables the application does not query directly. Check for file writes or command execution indicators, since the advisory notes remote code execution is reachable from the same path.
Rotate the credentials the system uses for its integrations and for database administration if access cannot be ruled out. Check for changes to call routing rules, which are an attractive persistence mechanism on telephony platforms because they survive ordinary service restarts.

References

Top comments (0)