CVE-2026-9586: Sangoma Switchvox
Sangoma Switchvox는 데이터베이스 운영 및 원격 코드 실행을 포함하여 단일 기술 요청을 사용하여 백엔드 PostgreSQL 데이터베이스에 대한 임의 SQL 선언을 실행하는 비공식적 인 원격 공격자를 허용하는 SQL 주입 취약점을 포함합니다.
CISA (English)
Sangoma Switchvox contains a SQL injection vulnerability which allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.
- 공급업체
- Sangoma
- 제품
- Switchvox
- 취약점
- Sangoma Switchvox SQL Injection Vulnerability
- 추가일
- 2026. 9. 2.
- CISA 조치 기한(미국 연방기관)
- 2026. 9. 5.
- 랜섬웨어 공격 악용
- 알 수 없음
- 약점(CWE)
- CWE-89
참고 자료
이 사이트는 정보 제공 목적으로 CISA 카탈로그를 요약한 것이며 보안 조언이 아닙니다. 공급업체 안내와 공식 권고를 따르세요.
최종 업데이트: · 카탈로그 버전 2026.10.02