CVE-2026-104811
Received Received - Intake

Remote Code Execution in DigitalCanion Configuration Portal

Vulnerability report for CVE-2026-104811, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: Switzerland Government Common Vulnerability Program

Description

DigitalCanion SA has discovered a vulnerability that allows remote attackers to execute arbitrary code on affected installations of the product. Authentication may be required to exploit this vulnerability. The specific flaw exists within the Configuration β†’ Services β†’ Music on Hold functionality of the web portal listening on TCP port 443. The application is intended to allow users to upload WAV audio files but fails to properly validate the uploaded file type. An attacker can exploit this behavior to upload a malicious shared object (.so) instead of a WAV file. When the uploaded file is subsequently processed by the affected component, attacker-controlled code is loaded and executed in the context of the affected process. This can result in remote code execution and potentially full compromise of the underlying Linux system.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
CWE-829 The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.
CWE-94 The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows remote attackers to execute arbitrary code on affected installations. The flaw exists in the Music on Hold feature of a web portal running on TCP port 443. The application fails to validate uploaded files properly, letting attackers upload malicious shared object files (.so) instead of WAV files. When processed, this executes attacker-controlled code in the system context, potentially leading to full system compromise.

Detection Guidance

Check for unauthorized uploads to the Music on Hold service on TCP port 443. Inspect WAV file uploads for unexpected file types like .so files. Monitor for suspicious processes loading shared objects from the upload directory.

Impact Analysis

An attacker could exploit this to run arbitrary code on your system, potentially gaining full control over the affected Linux system. This could lead to data theft, system damage, or further network compromise if the system is connected to other networks.

Mitigation Strategies

Disable the Music on Hold upload feature if not needed. Implement strict file type validation to only allow WAV files. Restrict write permissions to the upload directory. Update the application to patch the file validation flaw.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104811. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart