Mitel Product Security Advisory MISA-2026-0007

OpenScape UC Cross Reflected Site Scripting (XSS) Vulnerability

Advisory ID: MISA-2026-0007

Publish Date: 2026-07-22

Last Updated: 2026-07-22

Revision: 1.0

 

Summary

A reflected cross-site scripting (XSS) vulnerability has been identified in the OpenScape UC application, which, if successfully exploited, could allow an authenticated attacker to conduct a command injection attack due to insufficient input validation. A successful exploit of this vulnerability requires user interaction and could allow an attacker to execute arbitrary scripts on the system within the same privilege of the user.

The vulnerability severity is rated as high.

Mitel is recommending customers with affected product versions update to the available fixes as soon as feasible or apply the available workaround.

 

Affected Products and Solutions

This security advisory provides information on the following products:

PRODUCT NAME VERSION(S) AFFECTED SOLUTION(S) AVAILABLE 
OpenScape UC

V11 R0 to V11 R1 FR1 HF1 and 

V10 R6 FR17 HF1 and earlier

Upgrade to version V11 R1 FR2, or 

upgrade to version V10 R6 FR18, or subsequent releases.

Product statements are related only to supported product versions. Products which have reached End of Support status are not considered.

 

Vulnerability Severity

The following products have been identified as affected:

PRODUCT NAME CVE ID SEVERITY CVSS 3.1 BASE SCORE 
OpenScape UCMTLVULN-1618High / 8.0 AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

The vulnerability severity is rated as High.

Note: The above issue is referenced here by our internal tracking ID. A CVE identifier has been requested but is not yet assigned.

 

Mitigations / Workarounds

For customers who are not currently able to upgrade to the latest version in a timely manner, the risk may be mitigated by following the instructions found in the security Knowledge Base article.

 

Solution/ Recommended Action

This issue is addressed in Openscape UC version V10 R6 FR18 or version V11 R1 FR2. Customers are advised to upgrade to these or subsequent releases.

Please see Mitel Knowledge Base article KB000128300, “Openscape UC Security Update, MTLVULN-1618”

If you do not have access to this link, please contact your Mitel Authorized Partner for support. 

For further information, please contact Mitel Product Support.

 

Revision History

VersionDateDescription
1.02026-07-22Initial release

 

Publisher and Legal Disclaimer

Publisher: Mitel PSIRT / [email protected]

The information provided in this advisory is provided "as is" without warranty of any kind. The information is subject to change without notice. Mitel and its affiliates do not guarantee and accept no legal liability whatsoever arising from or connected to the accuracy, reliability, currency or completeness of the information provided. No part of this document can be reproduced or transmitted in any form or by any means - electronic or mechanical - for any purpose without written permission from Mitel Networks Corporation.

Stay One Step Ahead Get notifications of the latest security advisories sent right to your inbox every week!