Executive brief
Sangoma Switchvox is a business phone system management platform used by organizations to manage communication infrastructure. A critical SQL injection flaw allows remote attackers without authentication to directly manipulate the underlying database and execute code, potentially exposing customer data, disrupting phone service, or gaining control of the entire phone system.
Technical details
This is an unauthenticated SQL injection vulnerability in Sangoma Switchvox that permits remote code execution through the PostgreSQL backend database. The vulnerable component accepts unsanitized user input in a web-facing interface that is directly concatenated into SQL queries. An attacker can craft a specially-formatted HTTP request containing SQL payload to bypass authentication checks and execute arbitrary database commands. Because PostgreSQL can execute system commands through functions like exec() or similar mechanisms, this enables remote code execution on the server. The vulnerability requires no prior authentication or user interaction, and is currently being exploited in active attacks in the wild.
Affected products
- Sangoma Switchvox
Timeline
- 2026-09-02: disclosed
- exploited: Being actively exploited in the wild