Mitel Product Security Advisory MISA-2026-0006

MiCollab Command Injection Vulnerability

Advisory ID: MISA-2026-0006

Publish Date: 2026-07-22

Last Updated: 2026-07-22

Revision: 1.0

 

Summary

A command injection vulnerability has been identified in the Audio, Web, and Video Conferencing (AWV) component of Mitel MiCollab which, if successfully exploited, could allow an unauthenticated attacker to conduct a command injection attack due to insufficient parameter sanitization. A successful exploit of this vulnerability could allow an attacker to execute arbitrary commands and potentially gain control of the system.

The vulnerability severity is rated as Critical.

Mitel is recommending customers with affected product versions update to the available solutions as soon as feasible.

Credit is given to Hoang Tai of VNPT Cyber Immunity for highlighting this issue and bringing it to our attention.

 

Affected Products and Solutions

This security advisory provides information on the following products:

PRODUCT NAME VERSION(S) AFFECTED SOLUTION(S) AVAILABLE 
MiCollab

10.0 (10.0.0.26) to 10.2 SP1 FP2 (10.2.1.205) and 

9.8 SP3 FP2 (9.8.3.203) and earlier

Upgrade to version 10.3 (10.3.0.18) or subsequent releases.

Alternative Solution: Mitel provided patches available for releases 10.2 SP1 FP2 (10.2.1.205) and 9.8 SP3 FP2 (9.8.3.203). 

See the Security Knowledge Base article KB000128275 for instructions regarding the upgrade and applying the available patches.

Product statements are related only to supported product versions. Products that have reached End of Support status are not considered.

 

Vulnerability Severity

The following products have been identified as affected:

PRODUCT NAME CVE ID SEVERITY CVSS 3.1 BASE SCORE 
MiCollab MTLVULN-1694Critical / 9.8AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

The vulnerability severity is rated as critical.

Note: The above issue is referenced here by our internal tracking ID. A CVE identifier has been requested but is not yet assigned.

 

Solution/ Recommended Action

This issue is addressed in MiCollab version 10.3 (10.3.0.18). Also, Mitel provided patches are available for releases 10.2 SP1 FP2 (10.2.1.205) and 9.8 SP3 FP2 (9.8.3.203). Customers are advised to upgrade to these or subsequent releases.

Please see Mitel Security Knowledge Base article KB000128275, “MiCollab Security Update - MTLVULN-1694”, for detailed instructions regarding the upgrade and applying the available patches.

If you do not have access to this article, please contact your Mitel Authorized Partner for support.

For further information, please contact Mitel Product Support.

 

Revision History

VersionDateDescription
1.02026-07-22Initial release

 

Publisher and Legal Disclaimer

Publisher: Mitel PSIRT / [email protected]

The information provided in this advisory is provided "as is" without warranty of any kind. The information is subject to change without notice. Mitel and its affiliates do not guarantee and accept no legal liability whatsoever arising from or connected to the accuracy, reliability, currency or completeness of the information provided. No part of this document can be reproduced or transmitted in any form or by any means - electronic or mechanical - for any purpose without written permission from Mitel Networks Corporation.

Stay One Step Ahead Get notifications of the latest security advisories sent right to your inbox every week!