Vulnerability in Mitel Linux Virtual Machine Due to Unsafe Module Loading
CVE-2026-104809

8.4HIGH

Key Information:

Vendor

Mitel

Vendor
CVE Published:
5 October 2026

What is CVE-2026-104809?

A vulnerability has been identified in Mitel's Linux virtual machine that allows an attacker to leverage a predictable module name to load a malicious .so file instead of the legitimate module. The loading process fails to sufficiently verify the file's origin and integrity, enabling an attacker to execute code with the same privileges as the compromised process. This can lead to a complete system compromise and unauthorized access to sensitive information.

Affected Version(s)

Mitel MiVoice Office 400 Linux 11.0.96.0

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Brian Mariani from DigitalCanion SA
.