Arbitrary file upload in MiCollab and MiVoice Business Solution Virtual Instance (MiVB SVI) - #VU134875
Published: June 18, 2026
Vulnerability details
The vulnerability allows a remote attacker to upload arbitrary files with malicious content.
The vulnerability exists due to missing authentication mechanisms, insufficient file content sanitization, and lack of file type validation in the NuPoint Unified Messaging (NPM) component when handling file uploads. A remote attacker can upload a crafted file to upload arbitrary files with malicious content.
Affected software
MiVoice Business Solution Virtual Instance (MiVB SVI)
Remediation
MiVoice Business Solution Virtual Instance (MiVB SVI) - update to 2.1.0.9-4