Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-104809— Mitel MiVoice Office 400 Shared Object Hijacking Leading to Arbitrary Code Execution

Quick assessment

Affected
Mitel Mitel MiVoice Office 400
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Digital Canyon 发现了一个漏洞,该漏洞允许攻击者使系统加载由攻击者控制的 .so 文件,而非预期的合法模块。该加载机制依赖于可预测的模块名称,且未充分验证文件的来源或完整性。因此,一个使用预期名称的恶意共享对象可被特权进程加载。随后,该模块代码将在该进程的上下文和权限下执行,从而导致任意代码执行,并使 Mitel Linux 虚拟机遭到完全接管。

CVSS 8.4 · High

Possible ATT&CK Techniques 1 AI

T1055 · Process Injection
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-104809

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Mitel MiVoice Office 400 Shared Object Hijacking Leading to Arbitrary Code Execution
Source: CVE Program / CVE List V5
Vulnerability Description
DigitalCanion has discovered a vulnerability that allows an attacker to cause the system to load an attacker-controlled .so file instead of the expected legitimate module. The loading mechanism relies on a predictable module name without adequately verifying the file’s origin or integrity. A malicious shared object using the expected name can therefore be loaded by a privileged process. The module code then executes within the context and privileges of that process. This results in arbitrary code execution and full compromise of the Mitel Linux virtual machine.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/AU:Y/U:Amber
Source: CVE Program / CVE List V5
Vulnerability Type
文件名或路径的外部可控制
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Mitel Mitel MiVoice Office 400 11.0.96.0 -

II. Public POCs for CVE-2026-104809

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-104809

请登录查看更多情报信息。

Other References for CVE-2026-104809 (1)

Same Patch Batch · Mitel · 2026-10-05 · 8 CVEs total

CVE-2026-104805 8.5 HIGH Mitel MiVoice Office 400 Backup Restoration Arbitrary File Write Leading to Root Code Exec
CVE-2026-104706 8.4 HIGH Mitel MiVoice Office 400 view system files path traversal
CVE-2026-104810 8.4 HIGH Mitel MiVoice Office 400 File Management File Browser path traversal vulnerability
CVE-2026-104811 8.4 HIGH Mitel MiVoice Office 400 Music on Hold WAV File Upload Code Execution
CVE-2026-104806 5.5 MEDIUM Mitel MiVoice Office 400 System Logs Path Traversal Information Disclosure
CVE-2026-104807 1.9 LOW Mitel MiVoice Office 400 stored Cross-Site Scripting
CVE-2026-104808 1.9 LOW Mitel MiVoice Office 400 stored Cross-Site Scripting

IV. Related Vulnerabilities

V. Comments for CVE-2026-104809

No comments yet


Leave a comment