Mitel MiCollab AWV: unauthenticated command injection to full system compromise (CVSS 9.8, MTLVULN-1694, CVE pending)
Mitel ships an out-of-band fix for an unauthenticated RCE in MiCollab's conferencing component, no CVE yet, exposed appliances first
Defender actions
- Patch internet-facing Mitel MiCollab to 10.3.0.18, or apply the Mitel backport patches (KB000128275) for the 10.2 SP1 FP2 and 9.8 SP3 FP2 branches; the AWV command injection needs no authentication and no user interaction.
Analysis
Mitel's PSIRT advisory MISA-2026-0006 (2026-07-22, republished by CERT-FR as CERTFR-2026-AVI-0911 the next day) addresses a critical command-injection vulnerability, internally tracked as MTLVULN-1694 with a CVE requested but not yet assigned, in the Audio, Web, and Video Conferencing (AWV) component of on-premises MiCollab (Mitel, 2026-07-22). Per Mitel, insufficient parameter sanitisation in the AWV component lets an unauthenticated attacker inject and execute arbitrary OS commands, rated CVSS 3.1 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), meaning network-reachable, no credentials and no user interaction (Mitel, 2026-07-22). Affected releases run from 10.0.0.26 up to and including 10.2 SP1 FP2 (10.2.1.205) and 9.8 SP3 FP2 (9.8.3.203) and earlier; the fix ships in MiCollab 10.3.0.18, with Mitel-provided backport patches for the 10.2 SP1 FP2 and 9.8 SP3 FP2 branches (KB000128275) (CERT-FR, 2026-07-23). Neither Mitel nor CERT-FR reports exploitation at publication.
Cited evidence
A command injection vulnerability has been identified in the Audio, Web, and Video Conferencing (AWV) component of Mitel MiCollab which, if successfully exploited, could allow an unauthenticated attacker to conduct a command injection attack due to insufficient parameter sanitization.
Note: The above issue is referenced here by our internal tracking ID. A CVE identifier has been requested but is not yet assigned.
Sources2
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.