PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-104807 Mitel CVE debrief

A stored Cross-Site Scripting (XSS) vulnerability exists in the web portal of an unspecified product, allowing an authenticated attacker to inject persistent JavaScript or HTML content into the web application. The flaw is located in the 'Description' field under Configuration → Domains. An attacker can modify the content and behavior of the affected page when viewed by other users, potentially altering the page's appearance or constructing phishing scenarios.

Vendor
Mitel
Product
Mitel MiVoice Office 400
CVSS
LOW 1.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-05
Original CVE updated
2026-10-05
Advisory published
2026-10-05
Advisory updated
2026-10-05

Who should care

Defenders responsible for the affected system or component should assess exposure and prioritize verification and mitigation efforts. Defenders should care about CVE-2026-104807 because it represents a stored Cross-Site Scripting (XSS) vulnerability that could allow an authenticated attacker to inject persistent JavaScript or HTML content into the web application, potentially affecting the appearance or behavior of the affected page when viewed by other

Why it matters

Defenders should care about CVE-2026-104807 because it represents a stored Cross-Site Scripting (XSS) vulnerability that could allow an authenticated attacker to inject persistent JavaScript or HTML content into the web application, potentially affecting the appearance or behavior of the affected page when viewed by other users. The vulnerability exists in the 'Description' field under Configuration → Domains, and its exploitation requires authentication and user interaction. Defenders responsible for the affected system or component should assess exposure and prioritize verification and mitigation efforts.

  • Potential modification of page content or behavior
  • Possible construction of phishing scenarios within the application's trusted web context
  • Risk of displaying attacker-controlled content

Technical summary

The vulnerability exists in the web portal listening on TCP port 443, under Configuration → Domains, specifically in the 'Description' field. The application fails to properly validate or sanitize user-supplied input before storing and subsequently rendering the field. This allows an authenticated malicious user to inject persistent JavaScript or HTML content into the web application, potentially affecting the appearance or behavior of the affected page when viewed by other users. An attacker can modify the content and behavior of the affected page when viewed by other users, potentially altering the page's appearance or constructing phishing scenarios.

Defensive priority

Defenders should prioritize verifying the vulnerability's existence and scope within their environment, and apply patches or mitigations if available.

Recommended defensive actions

  • Verify the vulnerability's existence and scope within your environment
  • Apply patches or mitigations if available
  • Monitor for suspicious activity related to the affected component
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, but additional information from the vendor and other sources may be necessary to fully understand the issue. The vulnerability exists in the web portal listening on TCP port 443, under Configuration → Domains, specifically in the 'Description' field. The application fails to properly validate or sanitize user-supplied input before storing and subsequently rendering the field. Defenders should verify the vulnerability's existence and scope within their environment and

Sources and references

Verified primary and authoritative sources

  • CVE-2026-104807 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-104807

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-104807 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-104807

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.