CVE-2026-104809
Mitel MiVoice Office 400 Shared Object Hijacking Leading to Arbitrary Code Execution
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
DigitalCanion has discovered a vulnerability that allows an attacker to cause the system to load an attacker-controlled .so file instead of the expected legitimate module. The loading mechanism relies on a predictable module name without adequately verifying the fileβs origin or integrity. A malicious shared object using the expected name can therefore be loaded by a privileged process. The module code then executes within the context and privileges of that process. This results in arbitrary code execution and full compromise of the Mitel Linux virtual machine.
| CWE | CWE-73 CWE-494 CWE-829 CWE-426 CWE-427 |
| Vendor | mitel |
| Product | mitel mivoice office 400 |
| Published | Oct 5, 2026 |
Stay Ahead of the Next One
Get instant alerts for mitel mitel mivoice office 400
Be the first to know when new unknown vulnerabilities affecting mitel mitel mivoice office 400 are published β delivered to Slack, Telegram or Discord.
Get Free Alerts β
Free Β· No credit card Β· 60 sec setup
Affected Versions
Mitel / Mitel MiVoice Office 400
11.0.96.0
References
Credits
Brian Mariani from DigitalCanion SA