Path Traversal Vulnerability in DigitalCanion's Web Management Portal
CVE-2026-104806

5.5MEDIUM

Key Information:

Vendor

Mitel

Vendor
CVE Published:
5 October 2026

What is CVE-2026-104806?

DigitalCanion has identified a path traversal vulnerability within the Maintenance → System Logs feature of its web management portal. This security flaw allows attackers to bypass intended restrictions and access files beyond the designated directory. By exploiting the portal's inability to properly validate user-supplied file paths, an attacker can manipulate the path and gain access to potentially sensitive files stored outside the system logs directory. This could lead to unauthorized file downloads, posing significant risks to the security of the system and its applications.

Affected Version(s)

Mitel MiVoice Office 400 Linux 11.0.96.0

References

CVSS V4

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Brian Mariani from DigitalCanion SA
.