CVE-2026-104706: Mitel MiVoice Office 400 view system files path traversal
DigitalCanion has discovered a path traversal vulnerability that allows to view or download sensitive system files over the portal https://<ip>:8443 via menus Administration -> View Logs
Affected Software
Event History
Frequently Asked Questions
Which systems are exposed?
Mitel MiVoice Office 400 systems with the portal reachable over HTTPS on port 8443 are in scope. The vulnerable functionality is accessed through Administration -> View Logs.
What access does an attacker need?
The available information identifies the portal and administrative menu path but does not state whether authentication or administrative privileges are required. Exposure should therefore be assessed by checking who can reach the portal and who can access the View Logs function.
What is the impact of successful exploitation?
An attacker can view or download sensitive system files through a path traversal issue in the View Logs functionality.