Abstrakter Code als Symbol fuer eine Sicherheitsluecke

Critical Switchvox Flaw CVE-2026-9586: Attackers Hijack VoIP Systems via SQL Injection

Attackers can seize full control of Sangoma’s Switchvox VoIP phone system without any authentication – and that is already happening. Since 30 August 2026, honeypots have recorded active attacks against the CVE-2026-9586 flaw. On 1 September, researchers at Horizon3.ai published the technical details, sharply lowering the barrier to entry for further attackers.

What makes the flaw so dangerous

CVE-2026-9586 is an unauthenticated SQL injection that can be escalated to remote code execution. The unprotected /pa endpoint processes XML messages from IP phones and writes the PhoneIP field directly into a PostgreSQL query with no sanitisation whatsoever. A single crafted HTTP request is enough to run commands with database superuser privileges. The flaw carries a critical CVSS 4.0 score of 9.3.

Affected systems and ongoing attacks

The vulnerable release is Switchvox SMB Edition 8.3 (build 104997). According to Horizon3.ai, roughly 4,000 appliances are reachable from the internet, most of them in the United States. In observed attacks, threat actors pulled down reverse shells and then ran reconnaissance commands to exfiltrate system information. The incident remains ongoing – this is a preliminary assessment.

What administrators should do now

  • Update immediately to Switchvox 8.4.0.2 (released 14 July 2026).
  • Block the /pa endpoint from external access via firewall or reverse proxy until the patch is applied.
  • Review logs for suspicious POST requests to /pa and unusual outbound connections.

Sources: Horizon3.ai – CVE-2026-9586 Disclosure, SecurityOnline, SentinelOne Vulnerability Database.

Mastodon
Scroll to Top