H3-2026-0017¶
Sangoma Switchvox Unauthenticated SQL Injection Remote Code Execution Vulnerability
| Category | VULNERABILITY |
| Base Score | 9.8 |
Description¶
This vulnerability was discovered by Horizon3.ai researchers and responsibly disclosed to Sangoma as a /pa endpoint, a Polycom phone notification handler, concatenates the PhoneIP XML parameter directly into a single-quoted PostgreSQL string without parameterization. An attacker can use stacked queries to invoke COPY TO PROGRAM, executing arbitrary OS commands as the postgres superuser. Command output is exfiltrated via a path traversal vulnerability in the /dl endpoint that relies on a hardcoded authentication salt present on all installations.
Impact¶
Unauthenticated remote attackers with network access to the Switchvox web interface can execute arbitrary OS commands as the postgres superuser, leading to full host compromise.