VMTech
Discuss a project

Active exploitation targets critical Sangoma Switchvox SQL injection flaw

Active exploitation targets critical Sangoma Switchvox SQL injection flaw

Attackers are actively exploiting CVE-2026-9586, a critical unauthenticated SQL injection vulnerability in Sangoma Switchvox SMB Edition 8.3 (104997). The flaw has a CVSS score of 9.3 and can enable remote arbitrary code execution as the PostgreSQL superuser without credentials. Horizon3.ai has observed valid exploitation attempts since August 30, 2026.

Sangoma released a fix in Switchvox version 8.4.0.2 on July 14, 2026. Horizon3.ai estimates that about 4,000 Switchvox instances are exposed to the internet, with most located in the United States. The rapid activity seen across its honeypots indicates that internet-facing deployments are a priority target.

How the Switchvox flaw works

The issue lies in the /pa endpoint's processing of XML content beginning with <PolycomIPPhone>. CVE.org said the endpoint directly concatenates the user-controlled PhoneIP value into PostgreSQL queries without sanitisation or parameterisation.

A remote unauthenticated attacker can send one crafted request to execute arbitrary SQL statements against the backend database. The impact extends beyond database queries: the vulnerability can support database operations and remote code execution on the affected server.

Horizon3.ai said CVE-2026-9586 was one of 12 distinct Switchvox vulnerabilities it reported to Sangoma in April 2026. Security Risk Advisors Labs independently discovered and reported the same issue in May.

Observed impact and investigation points

Security Risk Advisors Labs demonstrated arbitrary database operations, including extracting database contents, modifying user records and escalating privileges to Switchvox web administrators. Its researchers also executed code on a target server and invoked a reverse shell.

One documented outcome is the theft of the cookie-signing key. An attacker with that key could forge authentication material for arbitrary users. In attacks against Horizon3.ai honeypots, operators deployed reverse shells and then executed Base64-encoded commands to enumerate running processes.

For systems with SSH access enabled, Horizon3.ai said the SQL injection payload may leave evidence in /var/log/switchvox/db-quirks.log. It also identified the address 176.65.148[.]184 in the activity; VirusTotal has flagged that address for port scanning, brute-force and exploitation activity.

Priority actions for organisations

Organisations running Switchvox SMB Edition should establish whether any instance is internet accessible, update to Switchvox 8.4.0.2, and review available logs for the documented payload and related suspicious activity. Teams should also assess whether administrative records, database contents or cookie-signing material could have been exposed, because successful exploitation can give an intruder both server-level execution and paths to impersonate users.

#cybersecurity#vulnerability#voip#incidentresponse
Open analytics
On the site 0 views
min read 3 02.09.2026
Instagram

Active exploitation targets critical Sangoma Switchvox SQL injection flaw

Open the post on Instagram ↗