CRITICALCVSS 9.8Vulnerability

CVE-2026-9586

Sangoma Switchvox contains a SQL injection vulnerability which allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.

Properties

severity
CRITICAL
product
Switchvox
vulnerabilityName
Sangoma Switchvox SQL Injection Vulnerability
cvss_score
9.8
cvss_severity
CRITICAL
epss_score
0.18979
dueDate
2026-09-05
retrieved_at
2026-09-27T13:53:59+00:00
requiredAction
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discon
dateAdded
2026-09-02
last_source
FIRST EPSS
score
9.8
cve_id
CVE-2026-9586
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
signal_observed_at
2026-09-11T17:54:47+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendorProject
Sangoma
published_at
2026-07-17T17:17:18.150
last_modified
2026-09-03T13:06:25.427
epss_percentile
0.97213

Related Entities (7)

INVOLVES (1)

←[Signal]

AFFECTS_PRODUCT (1)

→[Product]

DESCRIBES (1)

←[KEVEntry]Sangoma Switchvox SQL Injection Vulnerability

KNOWN_EXPLOITED (1)

→[Source]CISA KEV

ENRICHED_BY (1)

→[Source]FIRST EPSS

DESCRIBED_BY (1)

→[Source]NVD

HAS_WEAKNESS (1)

→[Weakness]Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-9586 (CVSS 9.8) — Ninja Signal Threat Intelligence | Ninja Signal