Vulnerability Description
An authenticated local file inclusion vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The play_file functionality accepts user-controlled input through the sound_path parameter and fails to properly validate file paths before accessing the underlying filesystem. By supplying absolute paths, an authenticated attacker can retrieve files outside the intended directory scope.
Related Weaknesses (CWE)
References
- https://github.com/sangoma/security-switchvox/security/advisories/GHSA-mhp4-x83p
- https://labs.sra.io/posts/switchvox/
FAQ
What is CVE-2026-9587?
CVE-2026-9587 is a documented vulnerability. An authenticated local file inclusion vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The play_file functionality accepts user-controlled input through the sound_path parameter and...
How severe is CVE-2026-9587?
CVSS scoring is not yet available for CVE-2026-9587. Check NVD for updates.
Is there a patch for CVE-2026-9587?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.