Path Traversal Vulnerability in DigitalCanion's Administration Portal
CVE-2026-104706

8.4HIGH

Key Information:

Vendor

Mitel

Vendor
CVE Published:
5 October 2026

What is CVE-2026-104706?

DigitalCanion has reported a significant path traversal vulnerability within its Administration Portal. This vulnerability allows unauthorized users to access and download sensitive system files through the web interface by navigating to the Administration -> View Logs menu. By exploiting this weakness, attackers can potentially compromise sensitive information, posing serious risks to the confidentiality and integrity of the system.

Affected Version(s)

Mitel MiVoice Office 400 Linux 11.0.96.0

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Brian Mariani from DigitalCanion SA
.