logo

PoC exploit chains Mitel MiCollab 0-day, auth-bypass bug to access sensitive files

ID: b71d1e3e-a460-559b-9861-09ba358f2ef6

STIX ID: report--b71d1e3e-a460-559b-9861-09ba358f2ef6

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2024-12-06

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

A watchTowr disclosure and published proof-of-concept detail three security issues in Mitel MiCollab — a fixed critical SQL injection (CVE-2024-35286), a fixed authentication bypass (CVE-2024-41713), and an unpatched post-auth arbitrary file-read zero-day that can be chained with the auth bypass to expose sensitive files (e.g., /etc/passwd); Mitel later published advisories and partial mitigations but the zero-day remained without a dedicated CVE or immediate patch at the time of reporting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.