Backup Restoration Vulnerability in DigitalCanion Products
CVE-2026-104805
What is CVE-2026-104805?
A significant vulnerability has been identified in DigitalCanion's backup restoration functionality that permits an attacker with access to the backup repository to introduce arbitrary files into the system during the restoration process. The issue arises from inadequate validation of paths, file types, and the integrity and authenticity of files contained within restored TGZ archives. This lax validation allows for the extraction of files that may be controlled by an attacker, leading to potential unauthorized access and arbitrary code execution on the underlying Linux system. Additionally, the lack of enforced backup passwords further diminishes the security of the backup mechanism, making it easier for malicious actors to exploit this vulnerability.
Affected Version(s)
Mitel MiVoice Office 400 Linux 11.0.96.0