HIGHVulnerability
Verified
Global
CISA KEV: Sangoma Switchvox — Sangoma Switchvox SQL Injection Vulnerability
·Source: CISA KEV
Updated:
Executive Summary
Sangoma Switchvox contains a SQL injection vulnerability which allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.
Analysis
Sangoma Switchvox contains a SQL injection vulnerability which allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution. Added to CISA Known Exploited Vulnerabilities catalog on 2026-09-02. Remediation due: 2026-09-05.