Description
DigitalCanion has discovered a path traversal vulnerability that allows an attacker to access files outside of the intended directory.




The specific flaw exists within the Maintenance → System Logs functionality of the web management portal listening on TCP port 443. The application fails to properly validate user-supplied file paths, allowing an attacker to manipulate the requested path and traverse the underlying directory structure.




By exploiting this vulnerability, an attacker can access and download files located outside the intended system logs directory, including potentially sensitive system and application files.
Published: 2026-10-05
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure via Path Traversal
Action: Update
AI Analysis

Impact

DigitalCanion identified a path traversal flaw in the Maintenance → System Logs feature of the Mitel MiVoice Office 400 web management portal, which listens on TCP port 443. The application does not validate user‑supplied file paths properly, allowing an attacker to manipulate the requested path and traverse outside the intended logs directory. Exploitation grants the attacker the ability to read and download files that should remain inaccessible, potentially exposing sensitive system or application data and compromising confidentiality.

Affected Systems

The vulnerability affects Mitel's MiVoice Office 400 product. No specific version range is provided in the CNA data, so all deployed instances are potentially impacted until a patch is applied.

Risk and Exploitability

The CVSS score of 5.5 indicates moderate severity; no EPSS score is available and the vulnerability is not listed in the CISA KEV dataset, suggesting that exploitation is not currently widespread. The likely attack vector requires remote access to the HTTPS management interface, but no authentication requirement is noted, implying that unauthenticated users could exploit the flaw if they can reach the portal. Because the flaw permits arbitrary file disclosure, it represents a significant confidentiality risk to any data stored outside the logs directory.

Generated by OpenCVE AI on October 5, 2026 at 10:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Mitel MiVoice Office 400 security update that resolves the path traversal issue.
  • Limit access to the web management portal by enabling IP‑based firewall rules or VPN tunnels to restrict traffic to trusted administrators.
  • Require strong, multi‑factor authentication for all accounts with permissions to the Maintenance → System Logs feature.
  • Continuously monitor HTTP requests for anomalous path traversal patterns and review downloaded files for suspicious content.

Generated by OpenCVE AI on October 5, 2026 at 10:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 05 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
Description DigitalCanion has discovered a path traversal vulnerability that allows an attacker to access files outside of the intended directory. The specific flaw exists within the Maintenance → System Logs functionality of the web management portal listening on TCP port 443. The application fails to properly validate user-supplied file paths, allowing an attacker to manipulate the requested path and traverse the underlying directory structure. By exploiting this vulnerability, an attacker can access and download files located outside the intended system logs directory, including potentially sensitive system and application files.
Title Mitel MiVoice Office 400 System Logs Path Traversal Information Disclosure
Weaknesses CWE-31
References
Metrics cvssV4_0

{'score': 5.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/AU:Y/R:A/V:D/RE:L/U:Amber'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: NCSC.ch

Published:

Updated: 2026-10-05T13:52:56.571Z

Reserved: 2026-10-02T13:47:45.135Z

Link: CVE-2026-104806

cve-icon Vulnrichment

Updated: 2026-10-05T13:51:55.350Z

cve-icon NVD

Status : Received

Published: 2026-10-05T09:17:09.540

Modified: 2026-10-05T14:17:16.190

Link: CVE-2026-104806

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T11:00:17Z

Weaknesses
  • CWE-31

    Path Traversal: 'dir\..\..\filename'