TL;DR
Mitel published two advisories. The first covers a MiCollab command injection bug rated critical at CVSS 9.8, which an unauthenticated attacker can reach over the network. The second covers a reflected XSS issue in OpenScape UC rated high at CVSS 8.0. Neither flaw has a CVE identifier yet.
Why It Matters
MiCollab sits at the center of enterprise voice and collaboration deployments. The critical bug needs no credentials, no privileges, and no user interaction. Mitel states plainly that a successful exploit could let an attacker run arbitrary commands and take control of the system.
History adds weight here. Earlier MiCollab flaws have landed in CISA’s Known Exploited Vulnerabilities catalog, so attackers clearly watch this product line.
How the Attacks Work
MiCollab (MTLVULN-1694)
The flaw lives in the Audio, Web, and Video Conferencing component. Insufficient parameter sanitization lets attacker-supplied input reach a command context. The CVSS vector confirms the worst case: network reachable, low complexity, no privileges, no user interaction, and full impact on confidentiality, integrity, and availability.
OpenScape UC (MTLVULN-1618)
This one is a reflected cross-site scripting issue caused by insufficient input validation. An attacker must already hold an account, and a victim must interact with the crafted request. Scripts then run at that user’s privilege level.
Affected Versions
- MiCollab 10.0 (10.0.0.26) through 10.2 SP1 FP2 (10.2.1.205), plus 9.8 SP3 FP2 (9.8.3.203) and earlier.
- OpenScape UC V11 R0 through V11 R1 FR1 HF1, plus V10 R6 FR17 HF1 and earlier.
Patch and Mitigation
MiCollab users should move to 10.3 (10.3.0.18) or later. Mitel also ships patches for 10.2 SP1 FP2 and 9.8 SP3 FP2, with instructions in knowledge base article KB000128275. Details sit in advisory MISA-2026-0006 on the MiCollab command injection flaw.
OpenScape UC users should upgrade to V11 R1 FR2 or V10 R6 FR18. A workaround exists in article KB000128300 for teams that cannot upgrade quickly, as described in advisory MISA-2026-0007 covering the OpenScape UC vulnerability.
Neither advisory reports exploitation in the wild, and no public proof-of-concept exists. Mitel credits Hoang Tai of VNPT Cyber Immunity for reporting the MiCollab issue.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.