HIGH🇵🇱 Wersja polska

CVE-2026-53902

CVSS 7.1v4.0pub. 2026-07-01upd. 2026-07-06

MCO does not properly enforce authorization checks in the /customer/servlet/mco/webapi/profile-sections/group-membership endpoint. An authenticated user can modify their group membership without proper authorization checks, allowing privilege escalation. An attacker can add themselves to arbitrary groups by supplying a valid group ID, which can be obtained via other application functionalities (e.g. /customer/servlet/mco/webapi/group/picker/groups), provided he has necessary permissions, or potentially inferred through brute-force techniques. Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 25.3.3.1 but may also affect other versions.

CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Mycomplianceoffice

    APP
    Mycomplianceoffice
    25.3.3.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
LPE
CWE
References

Related vulnerabilities

CVE-2026-53903MEDIUM5.3same product

MCO jest podatny na lukę Insecure Direct Object Reference (IDOR) w endpoincie /customer/servlet/mco/webapi/tra...

CVE-2026-53905MEDIUM5.3same product

MCO nie egzekwuje prawidłowo kontroli autoryzacji w endpoincie /customer/servlet/mco/webapi/admin-view-hierarc...

CVE-2026-53906MEDIUM5.1same product

MCO jest podatne na Path Disclosure i Path Traversal w funkcjonalności obsługi plików związanej z eksportem i ...

CVE-2026-53907MEDIUM4.8same product

MCO jest podatne na Stored XSS poprzez funkcjonalność przesyłania logo aplikacji. Atakujący, który ma możliwoś...

CVE-2026-53908MEDIUM6.9same product

MCO jest podatny na User Enumeration poprzez funkcjonalności związane z uwierzytelnianiem. Aplikacja zwraca ro...