Backup Restoration Vulnerability in DigitalCanion Products
CVE-2026-104805

8.5HIGH

Key Information:

Vendor

Mitel

Vendor
CVE Published:
5 October 2026

What is CVE-2026-104805?

A significant vulnerability has been identified in DigitalCanion's backup restoration functionality that permits an attacker with access to the backup repository to introduce arbitrary files into the system during the restoration process. The issue arises from inadequate validation of paths, file types, and the integrity and authenticity of files contained within restored TGZ archives. This lax validation allows for the extraction of files that may be controlled by an attacker, leading to potential unauthorized access and arbitrary code execution on the underlying Linux system. Additionally, the lack of enforced backup passwords further diminishes the security of the backup mechanism, making it easier for malicious actors to exploit this vulnerability.

Affected Version(s)

Mitel MiVoice Office 400 Linux 11.0.96.0

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Brian Mariani from DigitalCanion SA
.