πŸ” CVE Alert

CVE-2026-104809

UNKNOWN 0.0

Mitel MiVoice Office 400 Shared Object Hijacking Leading to Arbitrary Code Execution

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

DigitalCanion has discovered a vulnerability that allows an attacker to cause the system to load an attacker-controlled .so file instead of the expected legitimate module. The loading mechanism relies on a predictable module name without adequately verifying the file’s origin or integrity. A malicious shared object using the expected name can therefore be loaded by a privileged process. The module code then executes within the context and privileges of that process. This results in arbitrary code execution and full compromise of the Mitel Linux virtual machine.

CWE CWE-73 CWE-494 CWE-829 CWE-426 CWE-427
Vendor mitel
Product mitel mivoice office 400
Published Oct 5, 2026
Stay Ahead of the Next One

Get instant alerts for mitel mitel mivoice office 400

Be the first to know when new unknown vulnerabilities affecting mitel mitel mivoice office 400 are published β€” delivered to Slack, Telegram or Discord.

Get Free Alerts β†’ Free Β· No credit card Β· 60 sec setup

Affected Versions

Mitel / Mitel MiVoice Office 400
11.0.96.0

References

NVD β†— CVE.org β†— EPSS Data β†—
digitalcanion.com: https://digitalcanion.com/en/security-research/#vendor=mitel&status=cna

Credits

Brian Mariani from DigitalCanion SA