THREATOPS
THREAT OPSCVEs › CVE-2026-9586

CVE-2026-9586 — Sangoma Switchvox SQL Injection Vulnerability

CISA KEVExploited: confirmedSangoma

Sangoma Switchvox contains a SQL injection vulnerability which allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.

Vulnerability details

Related reporting