Interestana
Home/News/Critical Switchvox Flaw Allows Unauthenticated Remote Code Execution
The Hacker News3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Critical Switchvox Flaw Allows Unauthenticated Remote Code Execution

Critical Switchvox Flaw Allows Unauthenticated Remote Code Execution

Threat actors are actively exploiting a severe security vulnerability within Sangoma's Switchvox, an enterprise Voice over IP (VoIP) platform, which presents a significant risk of unauthenticated remote code execution. The vulnerability, identified as CVE-2026-9586, carries a critical CVSS score of 9.3, indicating its high severity and potential for exploitation. This specific flaw is an unauthenticated SQL injection vulnerability present in Sangoma Switchvox SMB Edition version 8.3 (build 104997). The nature of this SQL injection allows attackers to bypass authentication mechanisms and remotely execute arbitrary code on the affected server. The primary consequence of this exploitation is the ability for attackers to deploy reverse shells, which are a type of backdoor that allows an attacker to control a compromised system remotely. This control is established by having the compromised system initiate a connection back to the attacker's machine, effectively reversing the typical client-server communication model. The exploitation of CVE-2026-9586 does not require any prior authentication, meaning an attacker can initiate the attack without needing valid user credentials for the Switchvox system. This significantly lowers the barrier to entry for malicious actors, making it a prime target for widespread compromise. Sangoma Technologies, the company behind Switchvox, is known for providing unified communications solutions, including IP telephony, contact center software, and network access hardware. Switchvox is a business phone system designed for small to medium-sized businesses (SMBs) and enterprises, offering features such as call management, voicemail, conferencing, and integration with other business applications. The SMB Edition is tailored for smaller deployments. The exploitation of such critical vulnerabilities in business communication systems like Switchvox can have far-reaching implications. Compromised VoIP systems can be used for various malicious activities, including making unauthorized international calls, conducting toll fraud, eavesdropping on sensitive business communications, and as a pivot point to launch further attacks against an organization's internal network. The ability to deploy reverse shells without credentials means that once an attacker gains initial access through this vulnerability, they can maintain persistent access and potentially escalate their privileges within the network. Security researchers have noted that the unauthenticated nature of this SQL injection makes it particularly dangerous, as it can be exploited by automated scanning tools that probe for vulnerable systems across the internet. Organizations relying on Sangoma Switchvox SMB Edition 8.3 are strongly advised to apply any available patches or workarounds provided by Sangoma as soon as possible to mitigate the risk of exploitation. The detailed nature of the vulnerability, including the specific version and build number, allows for precise identification of at-risk systems. The CVSS score of 9.3 places this vulnerability among the most critical security issues, demanding immediate attention from system administrators. The successful deployment of reverse shells signifies a complete compromise of the system's integrity, allowing attackers to operate with a high degree of control.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next