PatchSiren cyber security CVE debrief
CVE-2026-104808 Mitel CVE debrief
A stored Cross-Site Scripting (XSS) vulnerability was discovered in an unknown vendor's web application, specifically on the Configuration → Users → Users List page, within the 'Microsoft Exchange mailbox' field. This flaw allows an authenticated attacker to inject persistent JavaScript or HTML content, leading to a denial-of-service condition. The vulnerability exists because user-supplied input is not properly validated or sanitized before being stored and rendered.
- Vendor
- Mitel
- Product
- Mitel MiVoice Office 400
- CVSS
- LOW 1.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-05
- Original CVE updated
- 2026-10-05
- Advisory published
- 2026-10-05
- Advisory updated
- 2026-10-05
Who should care
Defenders responsible for user-management functionality, web application security, and vulnerability management should assess exposure and prioritize verification and remediation efforts.
Why it matters
CVE-2026-104808 is a stored XSS vulnerability in an unknown vendor's web application that allows authenticated attackers to inject content, leading to denial-of-service. Defenders should prioritize verifying inventory, assessing exposure, and implementing input validation and sanitization.
- Denial-of-service condition within the application's user-management functionality
- Potential disruption to user property access
- Need for input validation and sanitization to prevent exploitation
- Verification of inventory and exposure required
Technical summary
The vulnerability exists within the web portal's user list feature, specifically in the 'Microsoft Exchange mailbox' field. An authenticated attacker can inject malicious JavaScript or HTML content, which is then stored and rendered, leading to a denial-of-service condition. This flaw allows an attacker to cause the payload to execute whenever the affected user properties are accessed, preventing access to the affected user properties and resulting in a denial-of-service condition within the application's user-management functionality.
Defensive priority
Defenders should prioritize verifying the presence of this vulnerability in their inventory and assess exposure, particularly for user-management functionality.
Recommended defensive actions
- Verify the presence of this vulnerability in your inventory
- Assess exposure, particularly for user-management functionality
- Implement input validation and sanitization for user-supplied data
- Monitor user-management functionality for anomalies
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, including its existence within the web portal's user list feature. However, specific affected versions and remediation steps are not provided.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-104808 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-104808
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-104808 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-104808
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://digitalcanion.com/en/security-research/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.