Directory Traversal Vulnerability in Mitel MiVoice Office 400
CVE-2026-104810
8.4HIGH
What is CVE-2026-104810?
The vulnerability arises from a directory traversal flaw within the web portal of Mitel MiVoice Office 400, specifically under the Maintenance → File Management → File Browser section. This issue permits authenticated attackers to navigate the filesystem beyond designated directories, enabling unauthorized file deletions. By leveraging this flaw, attackers can potentially erase critical files associated with both the Mitel application and the underlying Linux system, leading to severe disruptions such as denial-of-service conditions.
Affected Version(s)
Mitel MiVoice Office 400 Linux 11.0.96.0