CVE-2026-9585 Details
Description
An unauthenticated reflected cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition version 8.3 (104997). The application fails to properly sanitize the portal parameter supplied to the invalid_browser and invalid_browser_login handlers. User-supplied data is reflected into JavaScript generated by the application, allowing attacker-controlled script execution within a victim's browser.
A reflected cross-site scripting vulnerability has been identified in Sangoma Switchvox SMB Edition version 8.3 (104997). This vulnerability allows unauthenticated attackers to execute scripts in the context of the user's browser. The issue arises because the application does not properly sanitize the portal parameter sent to the invalid_browser and invalid_browser_login handlers. As a result, user-supplied data is reflected into JavaScript generated by the application, enabling the execution of attacker-controlled scripts.
Users are advised to update Sangoma Switchvox SMB to version 8.4.0.2 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 17, 2026CISA-ADP
Assessed Jul 17, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://labs.sra.io/posts/switchvox/ | Security Risk Advisors | AdvisoryBundleRemedy |
| https://sangomakb.atlassian.net/wiki/spaces/Switchvox/pages/1802371073/Switchvox+-+Release+Notes+Version+8.4.0.2+July+14+2026 | Security Risk Advisors | Release NotesVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Security Risk Advisors |
Affected Products
| Product | Versions |
|---|---|
| Sangoma Switchvox SMB | 8.3 (104997) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 17, 2026 | New CVE Received | Security Risk Advisors |
| Jul 17, 2026 | CVE Modified | CISA-ADP |
Volerion