CVE-2026-104806
Last modified
CVE-2026-104806 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. DigitalCanion has discovered a path traversal vulnerability that allows an attacker to access files outside of the intended directory. The specific flaw exists within the Maintenance → System Logs functionality of the web management portal listening on TCP port 443. The application fails to properly validate user-supplied file paths, allowing an attacker to manipulate the requested path and traverse the underlying directory structure. By exploiting this vulnerability, an attacker can access and download files located outside the intended system logs directory, including potentially sensitive system and application files.. EPSS estimates a 0.31% chance of exploitation in the next 30 days.
Description
DigitalCanion has discovered a path traversal vulnerability that allows an attacker to access files outside of the intended directory. The specific flaw exists within the Maintenance → System Logs functionality of the web management portal listening on TCP port 443. The application fails to properly validate user-supplied file paths, allowing an attacker to manipulate the requested path and traverse the underlying directory structure. By exploiting this vulnerability, an attacker can access and download files located outside the intended system logs directory, including potentially sensitive system and application files.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Mitel | Mitel MiVoice Office 400 | 11.0.96.0 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-104806?
How severe is CVE-2026-104806?
How do I fix CVE-2026-104806?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-104721Path-traversal vulnerability in QOS.CH Sarl Logback-classic …6.3
- CVE-2026-104733User Impersonation in ProcessOnes XMMP Server ejabberd <= 26…7.4
- CVE-2026-104747Unauthenticated PHP Object Injection in Haaken <= 1.5 versio…8.1
- CVE-2026-104757Editor Privilege Escalation in Import and export users and c…7.2
- CVE-2026-1048A weakness has been identified in LigeroSmart up to 6.1.26. …5.4
- CVE-2026-104805DigitalCanion has discovered a vulnerability in the backup r…8.5
- CVE-2026-104807DigitalCanion has discovered a stored Cross-Site Scripting (…1.9
- CVE-2026-104808DigitalCanion has discovered a stored Cross-Site Scripting (…1.9
- CVE-2026-104809DigitalCanion has discovered a vulnerability that allows an …8.4
- CVE-2026-104810This vulnerability allows remote attackers to delete sensiti…8.4
- CVE-2026-104811DigitalCanion SA has discovered a vulnerability that allows …8.4
- CVE-2026-104814Unauthenticated Cross Site Scripting (XSS) in Form Block <= …7.1
Are you affected by CVE-2026-104806?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
