Known vulnerabilities in MiCollab 9.8 SP1 FP2
Vendor:
Mitel
Software:
MiCollab
Version:
9.8 SP1 FP2
Software CPE:
cpe:2.3:a:mitel:micollab:*:*:*:*:*:*:*:*
Website:
https://www.mitel.com/
Total vulnerabilities:
12
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Vulnerabilities by Severity
Vulnerabilities (12)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU134866 - Improper Certificate Validation |
CWE-295 | High | 9.8 SP3 FP2 9.8.3.203, 10.2 SP1 FP2 10.2.1.205 | 18.06.2026 |
SB2026061848 |
||
| #VU134867 - Command injection |
CWE-77 | High | 9.8 SP3 FP2 9.8.3.203, 10.2 SP1 FP2 10.2.1.205 | 18.06.2026 |
SB2026061848 |
||
| #VU134868 - Command injection |
CWE-77 | High | 9.8 SP3 FP2 9.8.3.203, 10.2 SP1 FP2 10.2.1.205 | 18.06.2026 |
SB2026061848 |
||
| #VU134869 - Missing Authentication for Critical Function |
CWE-306 | High | 9.8 SP3 FP2 9.8.3.203, 10.2 SP1 FP2 10.2.1.205 | 18.06.2026 |
SB2026061848 |
||
| #VU134870 - Server-Side Request Forgery (SSRF) |
CWE-918 | High | 9.8 SP3 FP2 9.8.3.203, 10.2 SP1 FP2 10.2.1.205 | 18.06.2026 |
SB2026061848 |
||
| #VU134871 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') |
CWE-89 | High | 9.8 SP3 FP2 9.8.3.203, 10.2 SP1 FP2 10.2.1.205 | 18.06.2026 |
SB2026061848 |
||
| #VU134872 - Command injection |
CWE-77 | High | 9.8 SP3 FP2 9.8.3.203, 10.2 SP1 FP2 10.2.1.205 | 18.06.2026 |
SB2026061848 |
||
| #VU134873 - Command injection |
CWE-77 | High | 9.8 SP3 FP2 9.8.3.203, 10.2 SP1 FP2 10.2.1.205 | 18.06.2026 |
SB2026061848 |
||
| #VU134874 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
CWE-22 | High | 9.8 SP3 FP2 9.8.3.203, 10.2 SP1 FP2 10.2.1.205 | 18.06.2026 |
SB2026061848 |
||
| #VU134875 - Unrestricted Upload of File with Dangerous Type |
CWE-434 | High | 9.8 SP3 FP2 9.8.3.203, 10.2 SP1 FP2 10.2.1.205 | 18.06.2026 |
SB2026061848 |
||
| #VU134876 - Improper Restriction of XML External Entity Reference ('XXE') |
CWE-611 | High | 9.8 SP3 FP2 9.8.3.203, 10.2 SP1 FP2 10.2.1.205 | 18.06.2026 |
SB2026061848 |
||
| #VU134877 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') |
CWE-89 | High | 9.8 SP3 FP2 9.8.3.203, 10.2 SP1 FP2 10.2.1.205 | 18.06.2026 |
SB2026061848 |