CVE-2026-9585: Unauthenticated Reflected Cross-Site Scripting (XSS) in Switchvox SMB Web Portal
An unauthenticated reflected cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition version 8.3 (104997). The application fails to properly sanitize the portal parameter supplied to the invalidbrowser and invalidbrowserlogin handlers. User-supplied data is reflected into JavaScript generated by the application, allowing attacker-controlled script execution within a victim's browser.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9585?
CVE-2026-9585 has a severity rating of high, with a CVSS score of 8.6.
How do I fix CVE-2026-9585?
To fix CVE-2026-9585, upgrade Sangoma Switchvox SMB Edition to the latest patched version.
What type of vulnerability is CVE-2026-9585?
CVE-2026-9585 is an unauthenticated reflected cross-site scripting (XSS) vulnerability.
Which software is affected by CVE-2026-9585?
CVE-2026-9585 affects Sangoma Switchvox SMB Edition version 8.3.
When was CVE-2026-9585 published?
CVE-2026-9585 was published on July 17, 2026.