Sangoma Switchvox, an enterprise VoIP platform, has been hit by a critical vulnerability that could allow attackers to deploy reverse shells without credentials. This vulnerability, CVE-2026-9586, is a severe security flaw that could have far-reaching consequences for organizations using Switchvox. The issue lies in an unauthenticated SQL injection vulnerability in the SMB Edition 8.3 (104997) of Switchvox, which can lead to remote code execution as the PostgreSQL superuser without any credentials. This is a significant concern, as it allows attackers to perform arbitrary database operations and even execute code on the server, potentially leading to a reverse shell being invoked on the target machine.
The vulnerability was reported to Sangoma in April 2026 and has since been exploited in the wild. Security Risk Advisors (SRA) Labs discovered and reported the same vulnerability in May, demonstrating its severity. They were able to perform arbitrary database operations, extract database contents, modify user records, and escalate privileges to Switchvox web administrators. One of the most concerning aspects of this exploit is the ability to exfiltrate the cookie signing key to an external server, enabling attackers to forge authentication material for arbitrary users.
The attack involves deploying reverse shells on compromised systems and then using Base64-encoded commands to enumerate running processes. Indicators of compromise include evidence of the SQL injection payload in the '/var/log/switchvox/db-quirks.log' file and the attacker IP address '176.65.148[.]184', which has been flagged on VirusTotal for various malicious activities. The rapid succession of exploit attempts from the same source IP suggests that most internet-exposed Switchvox instances are likely to have been targeted.
This incident highlights the importance of timely patching and the need for organizations to stay vigilant against emerging threats. It also underscores the potential risks associated with using outdated software, as this vulnerability was present in the SMB Edition 8.3 (104997) version of Switchvox. As a result, organizations should prioritize updating their software to the latest version, which includes patches for this critical flaw, to mitigate the risk of exploitation.