Skip to content

H3-2026-0017

Sangoma Switchvox Unauthenticated SQL Injection Remote Code Execution Vulnerability

Category VULNERABILITY
Base Score 9.8

Description

This vulnerability was discovered by Horizon3.ai researchers and responsibly disclosed to Sangoma as a 0-day. H3-2026-0017 is an unauthenticated remote code execution vulnerability affecting Sangoma Switchvox. The /pa endpoint, a Polycom phone notification handler, concatenates the PhoneIP XML parameter directly into a single-quoted PostgreSQL string without parameterization. An attacker can use stacked queries to invoke COPY TO PROGRAM, executing arbitrary OS commands as the postgres superuser. Command output is exfiltrated via a path traversal vulnerability in the /dl endpoint that relies on a hardcoded authentication salt present on all installations.

Impact

Unauthenticated remote attackers with network access to the Switchvox web interface can execute arbitrary OS commands as the postgres superuser, leading to full host compromise.

References