CVE-2021-26714: Critical severity mitel micontact center enterprise vulnerability
The Enterprise License Manager portal in Mitel MiContact Center Enterprise before 9.4 could allow a user to access restricted files and folders due to insufficient access control. A successful exploit could allow an attacker to view and modify application data via Directory Traversal.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-26714?
CVE-2021-26714 is a vulnerability in the Enterprise License Manager portal in Mitel MiContact Center Enterprise before 9.4.
What is the severity of CVE-2021-26714?
CVE-2021-26714 has a severity rating of 9.8 (critical).
How does CVE-2021-26714 affect Mitel MiContact Center Enterprise?
CVE-2021-26714 allows a user to access restricted files and folders in the Enterprise License Manager portal, leading to potential unauthorized viewing and modification of application data.
How can CVE-2021-26714 be exploited?
CVE-2021-26714 can be exploited through Directory Traversal.
Is there a fix for CVE-2021-26714?
Yes, updating Mitel MiContact Center Enterprise to version 9.4 or higher will fix CVE-2021-26714. It is recommended to apply the necessary patches as soon as possible.