Junglewise Threat Intelligence

CVE-2026-45362: Sangoma Switchvox cleartext SIP credentials in backup file

CVE-2026-45362 · Severity: low · CVSS 3.2 · Published 2026-05-12

Vendors: Sangoma.

Executive brief

Sangoma Switchvox, a business phone system (PBX), was found to store sensitive phone service credentials in unencrypted plain text within its system backup files. If an unauthorized person gains access to one of these backup files, they could steal the credentials used to connect the phone system to the external carrier. This could allow an attacker to make fraudulent long-distance calls, intercept incoming business calls, or spoof the company's caller ID, potentially leading to financial loss and reputational damage.

Technical details

Sangoma Switchvox prior to version 8.4 suffers from a cleartext storage vulnerability (CWE-312) within its proprietary .svb backup format. The backup files contain SIP trunk authentication usernames, passwords, carrier hostnames, and DID assignments without encryption or obfuscation. While the CVSS 3.1 score is rated as Low (3.2) due to the local access requirement to obtain the backup file, the impact of credential extraction is significant. An attacker with access to a backup file can extract these details to register directly with the upstream SIP carrier, enabling toll fraud, inbound call interception, and caller ID spoofing. This issue was remediated in Switchvox version 8.4.

Affected products

  • Sangoma Switchvox before 8.4

Timeline

  • 2026-05-11: disclosed: Coordinated disclosure initiated and CVE assigned
  • 2026-05-12: advisory: NVD publication date
  • 2026-05-12: patched: Remediation released in version 8.4

References

Related threats