Directory Traversal Vulnerability in Mitel MiVoice Office 400
CVE-2026-104810

8.4HIGH

Key Information:

Vendor

Mitel

Vendor
CVE Published:
5 October 2026

What is CVE-2026-104810?

The vulnerability arises from a directory traversal flaw within the web portal of Mitel MiVoice Office 400, specifically under the Maintenance → File Management → File Browser section. This issue permits authenticated attackers to navigate the filesystem beyond designated directories, enabling unauthorized file deletions. By leveraging this flaw, attackers can potentially erase critical files associated with both the Mitel application and the underlying Linux system, leading to severe disruptions such as denial-of-service conditions.

Affected Version(s)

Mitel MiVoice Office 400 Linux 11.0.96.0

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Brian Mariani from DigitalCanion SA
.