CVE-2026-9587: Authenticated Local File Inclusion (LFI) in Switchvox SMB Web Portal
An authenticated local file inclusion vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The playfile functionality accepts user-controlled input through the soundpath parameter and fails to properly validate file paths before accessing the underlying filesystem. By supplying absolute paths, an authenticated attacker can retrieve files outside the intended directory scope.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9587?
The severity of CVE-2026-9587 is rated as high with a score of 7.1.
How do I fix CVE-2026-9587?
To fix CVE-2026-9587, update to the latest version of Sangoma Switchvox SMB Edition that addresses this vulnerability.
What systems are affected by CVE-2026-9587?
CVE-2026-9587 affects Sangoma Switchvox SMB Edition version 8.3 (104997).
What is the nature of CVE-2026-9587?
CVE-2026-9587 is an authenticated local file inclusion (LFI) vulnerability that allows user-controlled input to manipulate file paths.
What could happen if CVE-2026-9587 is exploited?
Exploitation of CVE-2026-9587 could allow an attacker to access sensitive files on the server, potentially leading to further compromise.