CVE-2026-9588 Details
Description
A stored cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997) within the voicemail notification template functionality. The submit_modify_voicemail_template endpoint fails to properly sanitize HTML content supplied by authenticated users, allowing malicious JavaScript supplied through the template_text parameter to be stored server-side and subsequently rendered to other users.
A stored cross-site scripting vulnerability has been identified in Sangoma Switchvox SMB Edition 8.3 (104997). This vulnerability arises within the voicemail notification template feature, where the submit_modify_voicemail_template endpoint does not adequately sanitize HTML content provided by authenticated users. As a result, malicious JavaScript injected through the template_text parameter can be stored on the server and later executed in the browsers of other users.
Users can update Sangoma Switchvox SMB to version 8.4.0.2 or later to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 17, 2026CISA-ADP
Assessed Jul 17, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://labs.sra.io/posts/switchvox/ | Security Risk Advisors | AdvisoryBundleRemedy |
| https://sangomakb.atlassian.net/wiki/spaces/Switchvox/pages/1802371073/Switchvox+-+Release+Notes+Version+8.4.0.2+July+14+2026 | Security Risk Advisors | Release NotesVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Security Risk Advisors |
Affected Products
| Product | Versions |
|---|---|
| Sangoma Switchvox SMB | 8.3 (104997) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 17, 2026 | New CVE Received | Security Risk Advisors |
| Jul 17, 2026 | CVE Modified | CISA-ADP |
Volerion