CVE-2026-9586 is a critical unauthenticated SQL injection vulnerability in Sangoma Switchvox SMB Edition 8.3 (build 104997), scored 9.3 (Critical) under CVSS 4.0. The flaw allows a remote, unauthenticated attacker to execute arbitrary SQL statements — and escalate to remote code execution — against the backend PostgreSQL database via a single crafted HTTP request. Sangoma released version 8.4.0.2 on July 14, 2026, three days before this CVE was published; systems still running 8.3 (build 104997) remain vulnerable.
