CVE-2026-104811
Last modified
CVE-2026-104811 is a high-severity vulnerability rated 8.4/10 on the CVSS scale. DigitalCanion SA has discovered a vulnerability that allows remote attackers to execute arbitrary code on affected installations of the product. Authentication may be required to exploit this vulnerability. The specific flaw exists within the Configuration → Services → Music on Hold functionality of the web portal listening on TCP port 443. EPSS estimates a 0.19% chance of exploitation in the next 30 days.
Description
DigitalCanion SA has discovered a vulnerability that allows remote attackers to execute arbitrary code on affected installations of the product. Authentication may be required to exploit this vulnerability. The specific flaw exists within the Configuration → Services → Music on Hold functionality of the web portal listening on TCP port 443. The application is intended to allow users to upload WAV audio files but fails to properly validate the uploaded file type. An attacker can exploit this behavior to upload a malicious shared object (.so) instead of a WAV file. When the uploaded file is subsequently processed by the affected component, attacker-controlled code is loaded and executed in the context of the affected process. This can result in remote code execution and potentially full compromise of the underlying Linux system.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Mitel | Mitel MiVoice Office 400 | 11.0.96.0 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-104811?
How severe is CVE-2026-104811?
How do I fix CVE-2026-104811?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-104805DigitalCanion has discovered a vulnerability in the backup r…8.5
- CVE-2026-104806DigitalCanion has discovered a path traversal vulnerability …5.5
- CVE-2026-104807DigitalCanion has discovered a stored Cross-Site Scripting (…1.9
- CVE-2026-104808DigitalCanion has discovered a stored Cross-Site Scripting (…1.9
- CVE-2026-104809DigitalCanion has discovered a vulnerability that allows an …8.4
- CVE-2026-104810This vulnerability allows remote attackers to delete sensiti…8.4
- CVE-2026-104814Unauthenticated Cross Site Scripting (XSS) in Form Block <= …7.1
- CVE-2026-104843uv is a Python package and project manager written in Rust. …5.9
- CVE-2026-104844PostCSS Selector Parser is a CSS selector parser that integr…5.9
- CVE-2026-104845Seroval facilitates JS value stringification, including comp…7.5
- CVE-2026-104846Seroval facilitates JS value stringification, including comp…9.8
- CVE-2026-104847ProseMirror's view component renders and manages the editabl…8.5
Are you affected by CVE-2026-104811?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
