CVE-2026-104810: Mitel MiVoice Office 400 File Management File Browser path traversal vulnerability
This vulnerability allows remote attackers to delete sensitive files on vulnerable installations of Mitel MiVoice Office 400. Authentication is required to exploit this vulnerability.
The specific flaw exists within the web portal listening on TCP port 443, under Maintenance → File Management → File Browser, which is affected by a directory traversal vulnerability. By exploiting this vulnerability, an authenticated attacker can access and delete files outside of the intended directory, including files belonging to the Mitel application and the underlying Linux system. Deleting critical system or application files can result in a denial-of-service condition affecting the underlying system.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must be able to authenticate to the MiVoice Office 400 web portal. The affected functionality is exposed through the HTTPS service listening on TCP port 443.
What access does successful exploitation provide?
An authenticated attacker can traverse outside the intended File Browser directory and delete files belonging to the Mitel application or the underlying Linux system. Deletion of critical files can cause denial of service on the affected system.
Which feature should administrators restrict while assessing exposure?
The affected feature is Maintenance → File Management → File Browser in the web portal. Restrict access to the portal and limit File Browser access to trusted administrative users.