LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2022-26143: MiCollab, MiVoice Business Express Access Control Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 25, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Apr 15, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2022-26143 to its Known Exploited Vulnerabilities catalog on Mar 25, 2022, with a federal patch deadline of Apr 15, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

A vulnerability has been identified in MiCollab and MiVoice Business Express that may allow a malicious actor to gain unauthorized access to sensitive information and services, cause performance…

CVE-2022-26143 is an access-control weakness in Mitel MiCollab and MiVoice Business Express that can let an unauthenticated actor reach sensitive information and services, degrade performance, or cause a denial-of-service condition. These products are commonly used for unified communications, so exposure can affect both confidentiality of collaboration data and availability of voice and messaging services. Confirm exact impact and fixed releases against the vendor advisory.

How it works

The issue is tracked under CWE-306 (missing authentication for a critical function) and CWE-406 (insufficient control of network message volume). In products of this class, certain interfaces or services may accept requests without properly verifying the caller’s identity or may fail to limit how much traffic a single source can generate. An attacker who can reach the affected interface could therefore invoke functionality that should require authentication, obtain data or service access that was intended to be restricted, or flood the system in a way that slows or disrupts normal operation. Public detail on precise request formats or endpoints is limited; treat any internet-facing or poorly segmented MiCollab or MiVoice Business Express deployment as potentially reachable and verify behavior against Mitel’s advisory rather than assuming exploit mechanics.

Am I affected? How to find it in your systems

MiCollab and MiVoice Business Express typically run as on-premises or appliance-based unified-communications platforms, often integrated with telephony, directory, and collaboration services. Inventory steps:

For signs of exploitation, examine authentication and access logs for unexpected unauthenticated requests to administrative or service endpoints, sudden spikes in connection volume or resource use consistent with amplification or flooding, and anomalous access to sensitive configuration or user data. Correlate with IDS/IPS or NetFlow alerts around the time the vulnerability became widely known. Absence of clear indicators does not prove non-compromise; limited public telemetry signatures mean you should prioritize inventory and patching.

How to remediate

Apply the updates Mitel released for MiCollab and MiVoice Business Express exactly as described in the vendor advisory and CISA’s direction to apply updates per vendor instructions. After patching:

If you can't patch immediately

Until the vendor update can be installed, reduce exposure with compensating controls:

These measures lower risk but do not replace the patch.

If your data may have been exposed

Actively exploited access-control flaws in communications platforms can lead to unauthorized disclosure of configuration data, user information, or service credentials and may be a precursor to broader intrusion. Known ransomware use of this CVE is not documented, yet any confirmed or suspected compromise should trigger your incident-response process: isolate affected hosts, preserve logs, rotate credentials that may have been accessible, and assess whether sensitive collaboration or directory data left the environment. As a simple additional check, you can run a free exposure scan of your email addresses against known breach datasets to see whether associated accounts appear in prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMitel · MiCollab, MiVoice Business Express
WeaknessCWE-306
Added to CISA KEVMar 25, 2022
Federal patch deadlineApr 15, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities