SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-9585

HIGH · CVSS 8.6 EPSS 0.33%

Source: NVD + CISA KEV + EPSS · Published 2026-07-17 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

An unauthenticated reflected cross-site scripting (XSS) vulnerability in Sangoma Switchvox SMB Edition version 8.3 allows attackers to inject malicious scripts through improperly sanitized user input in the portal parameter. This could lead to unauthorized script execution in the victim's browser, potentially compromising sensitive user information. Organizations using this version of Switchvox should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-9585
Severity
HIGH
CVSS
8.6
EPSS
0.33%
Java

Original NVD Description

An unauthenticated reflected cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition version 8.3 (104997). The application fails to properly sanitize the portal parameter supplied to the invalid_browser and invalid_browser_login handlers. User-supplied data is reflected into JavaScript generated by the application, allowing attacker-controlled script execution within a victim's browser.