Switchvox pa endpoint SQL injection

Added: 09/02/2026
CVE: CVE-2026-9586

Background

Switchvox is a VoIP and Unified Communications phone system.

Problem

An SQL injection vulnerability exposed by the unauthenticated /pa endpoint could allow a remote attacker to execute arbitrary commands.

Resolution

Upgrade to Switchvox 8.4.0.2 or higher.

References

https://labs.sra.io/posts/switchvox/
https://horizon3.ai/attack-research/disclosures/cve-2026-9586-sangoma-switchvox-rce/

Platforms

Switchvox

Back to exploit index