cbcvebase.

Sangoma Switchvox Smb Edition vulnerabilities

4 known vulnerabilities affecting sangoma/switchvox_smb_edition.

Total CVEs
4
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL1HIGH3

Vulnerabilities

Page 1 of 1
CVE-2026-9586P1CRITICALCVSS 9.8KEVPoC≥ 8.3 (104997), < 8.4.0.22026-07-17
CVE-2026-9586 [CRITICAL] CWE-89 CVE-2026-9586: An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with and directly concatenates the user-controlled PhoneIP value into PostgreSQL queries without sanitization or parameterization. An unauthenticated remote attacker can execute arbitrary SQL statements
nvd
CVE-2026-9585P3HIGHCVSS 8.6≥ 8.3 (104997), < 8.4.0.22026-07-17
CVE-2026-9585 [HIGH] CWE-79 CVE-2026-9585: An unauthenticated reflected cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SM An unauthenticated reflected cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition version 8.3 (104997). The application fails to properly sanitize the portal parameter supplied to the invalid_browser and invalid_browser_login handlers. User-supplied data is reflected into JavaScript generated by the application, allowing attac
nvd
CVE-2026-9587P3HIGHCVSS 7.1≥ 8.3 (104997), < 8.4.0.22026-07-17
CVE-2026-9587 [HIGH] CWE-73 CVE-2026-9587: An authenticated local file inclusion vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104 An authenticated local file inclusion vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The play_file functionality accepts user-controlled input through the sound_path parameter and fails to properly validate file paths before accessing the underlying filesystem. By supplying absolute paths, an authenticated attacker can retrieve files
nvd
CVE-2026-9588P4HIGHCVSS 7.0≥ 8.3 (104997), < 8.4.0.22026-07-17
CVE-2026-9588 [HIGH] CWE-79 CVE-2026-9588: A stored cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (10499 A stored cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997) within the voicemail notification template functionality. The submit_modify_voicemail_template endpoint fails to properly sanitize HTML content supplied by authenticated users, allowing malicious JavaScript supplied through the template_text parameter t
nvd
Sangoma Switchvox Smb Edition vulnerabilities | cvebase