Stored Cross-Site Scripting Vulnerability in Mitel Web Application
CVE-2026-104807

1.9LOW

Key Information:

Vendor

Mitel

Vendor
CVE Published:
5 October 2026

What is CVE-2026-104807?

A stored Cross-Site Scripting (XSS) vulnerability has been identified in the Mitel web application, enabling authenticated attackers to inject persistent JavaScript or HTML content. This issue arises within the web portal on TCP port 443, specifically in the 'Description' field under Configuration → Domains. The application inadequately validates or sanitizes user input, permitting attackers to manipulate the content viewed by other users. By executing this attack, malicious users can alter the appearance of pages, display harmful content, and create deceptive phishing scenarios that exploit the website's trusted environment.

Affected Version(s)

Mitel MiVoice Office 400 Linux 11.0.96.0

References

CVSS V4

Score:
1.9
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Brian Mariani from DigitalCanion SA
.