CVE-2024-55550: Mitel MiCollab Path Traversal Vulnerability
Low severity, CVSS 2.7. Actively exploited: in CISA KEV since 2025-01-07. EPSS: 38.2% chance of exploitation in the next 30 days.
Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization. A successful exploit could allow the authenticated admin attacker to access resources that are constrained to the admin access level, and the disclosure is limited to non-sensitive system information. This vulnerability does not allow file modification or privilege escalation.
Affected products
- Mitel MiCollab: up to and including 9.8.1.201
Published 2024-12-10. Last modified 2026-08-04.