ctipilot.ch
← Back to the live brief
NOTABLENATOA2vulnerability

Mitel MiCollab AWV: unauthenticated command injection to full system compromise (CVSS 9.8, MTLVULN-1694, CVE pending)

discovered 2026-07-24 04:36 UTCrun 2026-07-24T0409Z-intel2 sourcesmulti-source

Mitel's PSIRT advisory MISA-2026-0006 (2026-07-22, republished by CERT-FR as CERTFR-2026-AVI-0911 the next day) addresses a critical command-injection vulnerability, internally tracked as MTLVULN-1694 with a CVE requested but not yet assigned, in the Audio, Web, and Video Conferencing (AWV) component of on-premises MiCollab (Mitel, 2026-07-22). Per Mitel, insufficient parameter sanitisation in the AWV component lets an unauthenticated attacker inject and execute arbitrary OS commands — rated CVSS 3.1 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), meaning network-reachable, no credentials and no user interaction (Mitel, 2026-07-22). Affected releases run from 10.0.0.26 up to and including 10.2 SP1 FP2 (10.2.1.205) and 9.8 SP3 FP2 (9.8.3.203) and earlier; the fix ships in MiCollab 10.3.0.18, with Mitel-provided backport patches for the 10.2 SP1 FP2 and 9.8 SP3 FP2 branches (KB000128275) (CERT-FR, 2026-07-23). Neither Mitel nor CERT-FR reports exploitation at publication.

A command injection vulnerability has been identified in the Audio, Web, and Video Conferencing (AWV) component of Mitel MiCollab which, if successfully exploited, could allow an unauthenticated attacker to conduct a command injection attack due to insufficient parameter sanitization.

Note: The above issue is referenced here by our internal tracking ID. A CVE identifier has been requested but is not yet assigned.

Mitel PSIRT (MISA-2026-0006) 2026-07-22

Defender actions

  • Patch internet-facing Mitel MiCollab to 10.3.0.18, or apply the Mitel backport patches (KB000128275) for the 10.2 SP1 FP2 and 9.8 SP3 FP2 branches — the AWV command injection needs no authentication and no user interaction.

ATT&CK mapping

1 technique mapped from the cited reporting · MITRE ATT&CK v19.1

Initial Access TA0001
T1190Exploit Public-Facing Application

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

overlap matrix · ATT&CK page ↗

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.