CVE-2026-104809

DigitalCanion has discovered a vulnerability that allows an attacker to cause the system to load an attacker-controlled .so file instead of the expected legitimate module. The loading mechanism relies on a predictable module name without adequately verifying the file’s origin or integrity. A malicious shared object using the expected name can therefore be loaded by a privileged process. The module code then executes within the context and privileges of that process. This results in arbitrary code execution and full compromise of the Mitel Linux virtual machine.

  • Published Oct 5, 2026
  • CVSS 8.4 high
  • 0.1% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-104809 at the National Vulnerability Database