An authenticated local file inclusion vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The play_file functionality accepts user-controlled input through the sound_path parameter and fails to properly validate file paths before accessing the underlying filesystem. By supplying absolute paths, an authenticated attacker can retrieve files outside the intended directory scope.
CVSS
No CVSS.
References
Configurations
No configuration.
History
17 Jul 2026, 17:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-17 17:17
Updated : 2026-07-17 18:04
NVD link : CVE-2026-9587
Mitre link : CVE-2026-9587
CVE.ORG link : CVE-2026-9587
JSON object : View
Products Affected
No product.
CWE
CWE-73
External Control of File Name or Path
