Active wild exploitation targeting an enterprise voice over IP management platform has been confirmed across global honeypot arrays. Threat actors transmit malformed XML parameters to execute arbitrary SQL commands, gain database administrator authority, and invoke reverse shell connections.
The vulnerability, tracked as CVE-2026-9586 with a CVSS score of 9.3, impacts Sangoma Switchvox SMB Edition 8.3. The bug resides in the /pa endpoint where user-controlled PhoneIP parameter values are concatenated directly into PostgreSQL database queries without sanitization. Unauthenticated remote attackers submit single crafted HTTP POST requests to execute arbitrary SQL statements as the PostgreSQL superuser, extracting cookie signing keys to forge web session tokens and deploying Base64-encoded command payloads to establish interactive reverse shells.
Compromising central telecommunications servers creates severe internal voice eavesdropping and host security risks. Because Switchvox servers process call routing tables, voicemail archives, and active directory integration keys, an unauthenticated superuser takeover allows adversaries to intercept corporate communications, forge administrative sessions, and pivot into corporate subnets.
– Force immediate maintenance upgrades across all Sangoma Switchvox server installations to patched version 8.4.0.2 or higher.
– Inspect web server logs and database log paths at /var/log/switchvox/db-quirks.log for evidence of malformed SQL injection payloads.
– Restrict public internet visibility of Switchvox management interfaces using pre-authenticated zero trust access proxies.
– Rotate database access credentials, web cookie signing keys, and administrative user account passwords across affected appliances.
Enterprise telecommunications security depends on rigid query parameterization and prompt patch installation to ensure VoIP management platforms remain protected from unauthenticated SQL injection. #CodeDefence #Sangoma #Switchvox #SQLi #VoIPSecurity #RCE #AppSec #PatchManagement
/
