Exploited Vulnerabilities Daily
🌐 日本語

← 新着一覧

CVE-2026-9586: Sangoma Switchvox

Sangoma Switchvox は SQL インジェクションの脆弱性を含んでおり、未認証のリモートアサーチャが、データベースの操作やリモートコードの実行など、単一の crafted リクエストを使用してバックエンド PostgreSQL データベースに対して任意の SQL ステートメントを実行することを可能にします。

CISA (English)

Sangoma Switchvox contains a SQL injection vulnerability which allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.

ベンダー
Sangoma
製品
Switchvox
脆弱性
Sangoma Switchvox SQL Injection Vulnerability
追加日
2026/09/02
CISA対応期限(米国連邦機関向け)
2026/09/05
ランサムウェア攻撃での利用
不明
弱点(CWE)
CWE-89

参考情報

当サイトはCISAのカタログを情報提供のために要約したもので、セキュリティ上の助言ではありません。ベンダーの案内と公式のアドバイザリーに従ってください。

最終更新: · カタログのバージョン 2026.10.02