Switchvox pa endpoint SQL injection
Added: 09/02/2026CVE: CVE-2026-9586
Background
Switchvox is a VoIP and Unified Communications phone system.Problem
An SQL injection vulnerability exposed by the unauthenticated /pa endpoint could allow a remote attacker to execute arbitrary commands.Resolution
Upgrade to Switchvox 8.4.0.2 or higher.References
https://labs.sra.io/posts/switchvox/https://horizon3.ai/attack-research/disclosures/cve-2026-9586-sangoma-switchvox-rce/
Platforms
SwitchvoxBack to exploit index
