PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-104808 Mitel CVE debrief

A stored Cross-Site Scripting (XSS) vulnerability was discovered in an unknown vendor's web application, specifically on the Configuration → Users → Users List page, within the 'Microsoft Exchange mailbox' field. This flaw allows an authenticated attacker to inject persistent JavaScript or HTML content, leading to a denial-of-service condition. The vulnerability exists because user-supplied input is not properly validated or sanitized before being stored and rendered.

Vendor
Mitel
Product
Mitel MiVoice Office 400
CVSS
LOW 1.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-05
Original CVE updated
2026-10-05
Advisory published
2026-10-05
Advisory updated
2026-10-05

Who should care

Defenders responsible for user-management functionality, web application security, and vulnerability management should assess exposure and prioritize verification and remediation efforts.

Why it matters

CVE-2026-104808 is a stored XSS vulnerability in an unknown vendor's web application that allows authenticated attackers to inject content, leading to denial-of-service. Defenders should prioritize verifying inventory, assessing exposure, and implementing input validation and sanitization.

  • Denial-of-service condition within the application's user-management functionality
  • Potential disruption to user property access
  • Need for input validation and sanitization to prevent exploitation
  • Verification of inventory and exposure required

Technical summary

The vulnerability exists within the web portal's user list feature, specifically in the 'Microsoft Exchange mailbox' field. An authenticated attacker can inject malicious JavaScript or HTML content, which is then stored and rendered, leading to a denial-of-service condition. This flaw allows an attacker to cause the payload to execute whenever the affected user properties are accessed, preventing access to the affected user properties and resulting in a denial-of-service condition within the application's user-management functionality.

Defensive priority

Defenders should prioritize verifying the presence of this vulnerability in their inventory and assess exposure, particularly for user-management functionality.

Recommended defensive actions

  • Verify the presence of this vulnerability in your inventory
  • Assess exposure, particularly for user-management functionality
  • Implement input validation and sanitization for user-supplied data
  • Monitor user-management functionality for anomalies
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, including its existence within the web portal's user list feature. However, specific affected versions and remediation steps are not provided.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-104808 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-104808

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-104808 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-104808

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.