Unauthenticated root, from the network, on an appliance that terminates an organization's voice and conferencing traffic.
Synack Red Teamer @mcipekci found that Mitel MiCollab was extracting the Common Name from an attacker-supplied TLS certificate and running it as a shell command, even though the certificate itself was ultimately rejected as invalid. CVSS 10.0, off two SOAP requests with nothing malicious-looking in either one.
The takeaway: anything that exists to establish trust, a certificate, a JWT, a SAML assertion, is not itself trusted input until it's been verified.
Full technical breakdown in Exploits Explained: hubs.ly/Q04tt3DV0
Aug 18, 2026 · 8:26 PM UTC
11
59
10,472

