CVE-2026-9587: An authenticated local file inclusion vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The play_file functionality accepts user-controlled input through the soun
An authenticated local file inclusion vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The play_file functionality accepts user-controlled input through the sound_path parameter and fails to properly validate file paths before accessing the underlying filesystem. By supplying absolute paths, an authenticated attacker can retrieve files outside the intended directory scope.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-9587
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-95870.23% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 14% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-9587 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for An authenticated local
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highCVE-2026-66415: Leantime 3.6.2 contains a server-side request forgery and local file inclusion vulnerability t…nvd · 2026-07-30
- mediumCVE-2026-44105: The credentials for the local user "user-app" may be exposed in log files, potentially enablin…nvd · 2026-07-30
- unknownCVE-2026-63302: Quick.CMS is vulnerable to Local File Inclusion (LFI) in the admin.php endpoint via the p para…nvd · 2026-07-28
- unknownCVE-2026-12504: Improper Authentication (CWE-287) in the PAM configuration in Loytec LIP-ME201C, L-INX, L-GATE…nvd · 2026-07-24
- highCVE-2026-14172: Rapid7 InsightVM, Nexpose, and the Insight Agent execute discovered executables during authent…nvd · 2026-07-24
- criticalCVE-2026-63732: 9router 0.4.59 (fixed in 0.4.60) contains a chain of vulnerabilities: a hardcoded default pass…nvd · 2026-07-23
More from NVD Recent CVEs
- unknownCVE-2026-55735: Improper Verification of Cryptographic Signature in ueberauth guardian allows an unauthenticat…2026-08-01
- unknownCVE-2026-55734: Allocation of Resources Without Limits or Throttling vulnerability in ueberauth guardian (Guar…2026-08-01
- unknownCVE-2026-55733: Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of se…2026-08-01
- unknownCVE-2026-54894: Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of se…2026-08-01
- mediumCVE-2026-67355: guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only cookie scope, storing the …2026-08-01