CVE-2026-104810
Received Received - Intake

Directory Traversal in Mitel MiVoice Office 400

Vulnerability report for CVE-2026-104810, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: Switzerland Government Common Vulnerability Program

Description

This vulnerability allows remote attackers to delete sensitive files on vulnerable installations of Mitel MiVoice Office 400. Authentication is required to exploit this vulnerability. The specific flaw exists within the web portal listening on TCP port 443, under Maintenance β†’ File Management β†’ File Browser, which is affected by a directory traversal vulnerability. By exploiting this vulnerability, an authenticated attacker can access and delete files outside of the intended directory, including files belonging to the Mitel application and the underlying Linux system. Deleting critical system or application files can result in a denial-of-service condition affecting the underlying system.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mitel mivoice_office_400 *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-31 The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize 'dir\..\..\filename' (multiple internal backslash dot dot) sequences that can resolve to a location that is outside of that directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Mitel MiVoice Office 400 allows authenticated remote attackers to delete sensitive files via a directory traversal flaw in the web portal's file management section. Exploitation could lead to deletion of critical system or application files, causing a denial-of-service condition.

Detection Guidance

Check if the Mitel MiVoice Office 400 web portal is accessible on TCP port 443. Inspect the File Browser under Maintenance for unauthorized file access or deletion attempts. Monitor system logs for suspicious activity related to file management.

Impact Analysis

If exploited, this vulnerability could cause system crashes or loss of functionality by deleting essential files. It requires authentication but could disrupt operations if an attacker gains access to an authenticated session.

Mitigation Strategies

Restrict access to the web portal to trusted users only. Disable the File Browser feature if not required. Apply patches or updates from Mitel to fix the directory traversal vulnerability. Monitor for any signs of exploitation or unauthorized file deletions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104810. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart