Description
DigitalCanion has discovered a path traversal vulnerability that allows to view or download sensitive system files over the portal https://<ip>:8443 via menus Administration -> View Logs
Published: 2026-10-05
Score: 8.4 High
EPSS: n/a
KEV: No
Impact: Information Disclosure
Action: Patch Now
AI Analysis

Impact

A path traversal flaw exists in Mitel MiVoice Office 400 that allows an attacker to view or download arbitrary system files through the web portal by navigating to Administration → View Logs. The vulnerability permits reading sensitive configuration files or binaries, resulting in confidentiality loss if accessed by an unauthorized user.

Affected Systems

Mitel MiVoice Office 400 is affected; no specific versions are listed, so any installation of this product is potentially vulnerable.

Risk and Exploitability

The CVSS score of 8.4 indicates a high severity exposure. EPSS data is not available, and the vulnerability is not in the CISA KEV catalog. The flaw is exploitable over the HTTPS portal, likely requiring authenticated access to the Administration view; a victim must be able to log into the web interface. An attacker with administrative or privileged access to the portal can traverse directories and retrieve system files, potentially leading to further exploitation. The high score combined with remote availability makes this a significant risk for affected deployments.

Generated by OpenCVE AI on October 5, 2026 at 09:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor’s patch or upgrade to a version that mitigates the path‑traversal flaw.
  • If a patch is not yet available, limit portal access to trusted IP addresses and disable the Administration → View Logs menu for users who do not need it.
  • Implement file‑system permissions and web‑application firewall rules that block traversal requests and log unauthorized file access attempts.

Generated by OpenCVE AI on October 5, 2026 at 09:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 08:30:00 +0000

Type Values Removed Values Added
Description DigitalCanion has discovered a path traversal vulnerability that allows to view or download sensitive system files over the portal https://<ip>:8443 via menus Administration -> View Logs
Title Mitel MiVoice Office 400 view system files path traversal
Weaknesses CWE-31
References
Metrics cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/AU:Y/U:Amber'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: NCSC.ch

Published:

Updated: 2026-10-05T08:25:16.221Z

Reserved: 2026-10-02T10:24:42.984Z

Link: CVE-2026-104706

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T09:17:09.167

Modified: 2026-10-05T09:17:09.167

Link: CVE-2026-104706

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T09:30:10Z

Weaknesses
  • CWE-31

    Path Traversal: 'dir\..\..\filename'