2026-07-24 · view entry permalink →
Mitel MiCollab AWV: unauthenticated command injection to full system compromise (CVSS 9.8, MTLVULN-1694, CVE pending)
Mitel's PSIRT advisory MISA-2026-0006 (2026-07-22, republished by CERT-FR as CERTFR-2026-AVI-0911 the next day) addresses a critical command-injection vulnerability, internally tracked as MTLVULN-1694 with a CVE requested but not yet assigned, in the Audio, Web, and Video Conferencing (AWV) component of on-premises MiCollab (Mitel, 2026-07-22). Per Mitel, insufficient parameter sanitisation in the AWV component lets an unauthenticated attacker inject and execute arbitrary OS commands, rated CVSS 3.1 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), meaning network-reachable, no credentials and no user interaction (Mitel, 2026-07-22). Affected releases run from 10.0.0.26 up to and including 10.2 SP1 FP2 (10.2.1.205) and 9.8 SP3 FP2 (9.8.3.203) and earlier; the fix ships in MiCollab 10.3.0.18, with Mitel-provided backport patches for the 10.2 SP1 FP2 and 9.8 SP3 FP2 branches (KB000128275) (CERT-FR, 2026-07-23). Neither Mitel nor CERT-FR reports exploitation at publication.
A command injection vulnerability has been identified in the Audio, Web, and Video Conferencing (AWV) component of Mitel MiCollab which, if successfully exploited, could allow an unauthenticated attacker to conduct a command injection attack due to insufficient parameter sanitization.
Note: The above issue is referenced here by our internal tracking ID. A CVE identifier has been requested but is not yet assigned.