Remote Code Execution Vulnerability in Mitel Web Portal Music on Hold Feature
CVE-2026-104811

8.4HIGH

Key Information:

Vendor

Mitel

Vendor
CVE Published:
5 October 2026

What is CVE-2026-104811?

DigitalCanion SA identified a flaw in the Mitel web portal's Music on Hold functionality that enables remote attackers to execute arbitrary code. This vulnerability arises from improper validation of uploaded file types, allowing malicious users to upload a shared object (.so) file disguised as a WAV audio file. Once processed, the attacker-controlled code is executed within the context of the application, potentially compromising the underlying Linux system.

Affected Version(s)

Mitel MiVoice Office 400 Linux 11.0.96.0

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Brian Mariani from DigitalCanion SA
.