Description
DigitalCanion has discovered a vulnerability in the backup restoration functionality that allows an attacker with access to the configured backup repository to introduce arbitrary files into the system during restoration.




The specific flaw exists within the backup restoration mechanism, which fails to properly validate the paths, file types, integrity, and authenticity of files contained within a restored TGZ archive. The application does not perform file-signature verification before extracting the archive, allowing a specially crafted backup to contain attacker-controlled files.




An attacker with access to the backup SFTP or other configured repository can therefore provide a malicious TGZ archive that, when restored by the system, may place arbitrary files on the underlying Linux system. Depending on the location and permissions of the extracted files, this behavior can potentially be leveraged to achieve arbitrary code execution with root privileges and compromise the underlying virtual machine.




The absence of enforced backup passwords further reduces the protection provided by the backup mechanism and may facilitate unauthorized access to the repository.
Published: 2026-10-05
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Root Code Execution via Arbitrary File Write
Action: Immediate Patch
AI Analysis

Impact

A flaw in the backup restoration function of Mitel MiVoice Office 400 allows an attacker who can access the backup repository to incorporate attacker-controlled files during extraction. The mechanism does not validate extraction paths, file types, integrity, or authenticity, nor does it enforce backup passwords. Because the restored files can be placed with arbitrary paths and permissions on the underlying Linux system, an attacker can overwrite privileged files or place executable binaries, potentially leading to full root compromise. The weakness relies on improper file handling and missing signature verification and is classified under CWE‑22, CWE‑434, CWE‑73, CWE‑345, and CWE‑494.

Affected Systems

Mitel MiVoice Office 400 – all releases that use the default backup restoration routine, with no version differentiation available.

Risk and Exploitability

The CVSS score of 8.5 indicates high severity, and although the EPSS score is not available, the vulnerability can be exploited by anyone with read/write access to the backup repository, such as an SFTP user or another application that writes to the repository. The lack of a KEV listing does not diminish the risk, as the attack requires no special conditions. Attacks are feasible via a crafted TGZ archive and can result in arbitrary code execution with system privileges.

Generated by OpenCVE AI on October 5, 2026 at 10:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any vendor patch or update that addresses arbitrary file writes during backup restoration
  • Restrict backup repository access to trusted users, enforce strong authentication, and disable SFTP if not required
  • Implement path and file type validation for TGZ restoration and require signature verification before extraction

Generated by OpenCVE AI on October 5, 2026 at 10:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 05 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
Description DigitalCanion has discovered a vulnerability in the backup restoration functionality that allows an attacker with access to the configured backup repository to introduce arbitrary files into the system during restoration. The specific flaw exists within the backup restoration mechanism, which fails to properly validate the paths, file types, integrity, and authenticity of files contained within a restored TGZ archive. The application does not perform file-signature verification before extracting the archive, allowing a specially crafted backup to contain attacker-controlled files. An attacker with access to the backup SFTP or other configured repository can therefore provide a malicious TGZ archive that, when restored by the system, may place arbitrary files on the underlying Linux system. Depending on the location and permissions of the extracted files, this behavior can potentially be leveraged to achieve arbitrary code execution with root privileges and compromise the underlying virtual machine. The absence of enforced backup passwords further reduces the protection provided by the backup mechanism and may facilitate unauthorized access to the repository.
Title Mitel MiVoice Office 400 Backup Restoration Arbitrary File Write Leading to Root Code Execution
Weaknesses CWE-22
CWE-345
CWE-434
CWE-494
CWE-73
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/AU:Y/R:U/V:D/RE:M/U:Amber'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: NCSC.ch

Published:

Updated: 2026-10-05T12:57:11.157Z

Reserved: 2026-10-02T13:47:44.296Z

Link: CVE-2026-104805

cve-icon Vulnrichment

Updated: 2026-10-05T12:57:07.811Z

cve-icon NVD

Status : Received

Published: 2026-10-05T09:17:09.380

Modified: 2026-10-05T13:16:51.523

Link: CVE-2026-104805

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T11:00:17Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

  • CWE-345

    Insufficient Verification of Data Authenticity

  • CWE-434

    Unrestricted Upload of File with Dangerous Type

  • CWE-494

    Download of Code Without Integrity Check

  • CWE-73

    External Control of File Name or Path