CVE-2025-67822: Mitel MiVoice Mx-One
Critical severity, CVSS 9.4. EPSS: 0.4% chance of exploitation in the next 30 days.
A vulnerability in the Provisioning Manager component of Mitel MiVoice MX-ONE 7.3 (7.3.0.0.50) through 7.8 SP1 (7.8.1.0.14) could allow an unauthenticated attacker to conduct an authentication bypass attack due to improper authentication mechanisms. A successful exploit could allow an attacker to gain unauthorized access to user or admin accounts in the system.
Affected products
- Mitel MiVoice Mx-One: from 7.3, before 7.8 (fixed in 7.8); version 7.8 only
Published 2026-01-15. Last modified 2026-06-17.