Planet Briefing

First published · Last updated

CVE-2026-9586: Sangoma Switchvox SQL Injection Vulnerability

An SQL injection in Sangoma Switchvox allows an unauthenticated remote attacker to execute arbitrary SQL statements and potentially achieve remote code execution against the backend PostgreSQL database. CISA advises applying vendor mitigations, following BOD 26-04 guidance for prioritizing updates and forensics, evaluating internet exposure, or discontinuing the product if mitigations are unavailable.

Categories: technology

Generated scores

Scores are based on the cited reporting and use a 1–10 scale. Read the methodology.

Confidence
9/10
Geographic reach
2/10
Global importance
2/10
Impact magnitude
6/10
Positivity
2/10
Urgency
6/10

Why it matters

Exploitation can lead to database compromise and remote code execution on affected systems, creating significant security and operational risk.

Location

Sources

Report an issue