Executive brief
Sangoma Switchvox is a business phone system (IP-PBX) used for corporate communications. A security flaw in the web portal allows a logged-in user to access sensitive system files that they should not be able to see. This could lead to the exposure of configuration data or other internal system information, potentially aiding further attacks on the organization's communication infrastructure.
Technical details
An authenticated local file inclusion (LFI) vulnerability exists in the 'play_file' functionality of Sangoma Switchvox SMB Edition. The application accepts user-controlled input via the 'sound_path' parameter but fails to validate or sanitize the file path before accessing the filesystem. By providing absolute file paths, an authenticated attacker with network access to the web portal can bypass directory restrictions to retrieve sensitive files from the server. This vulnerability is classified as CWE-73 (External Control of File Name or Path) and has been addressed in version 8.4.0.2.
Affected products
- Sangoma Switchvox SMB Edition 8.3 (104997) before 8.4.0.2
Timeline
- 2026-05-11: other: Vulnerability discovered and reported to vendor
- 2026-06-02: other: Vendor acknowledged the report
- 2026-07-14: patched: Vendor released version 8.4.0.2 to address the issue
- 2026-07-17: disclosed: Public advisory and CVE published