Server-Side Request Forgery (SSRF) in MiCollab and MiVoice Business Solution Virtual Instance (MiVB SVI) - #VU134870
Published: June 18, 2026
Vulnerability details
The vulnerability allows a remote attacker to leverage connections and permissions available to the host server.
The vulnerability exists due to insufficient restriction of user-provided URLs in the MiCollab Client Service component when processing user-supplied URLs. A remote attacker can submit a crafted URL to leverage connections and permissions available to the host server.
Affected software
MiVoice Business Solution Virtual Instance (MiVB SVI)
Remediation
MiVoice Business Solution Virtual Instance (MiVB SVI) - update to 2.1.0.9-4