CVE-2026-53905
גבוהה 7.1
תיאור (מקור, אנגלית)
MCO does not properly enforce authorization checks in the /customer/servlet/mco/webapi/admin-view-hierarchy/get-acl-tree-structure endpoint. An authenticated, low-privileged user can retrieve administrator access control structures without proper authorization checks. This may expose sensitive permission mappings and internal configuration details. Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 25.3.3.1 but may also affect other versions.
מדדים
- CVSS 3.1
-
7.1 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N - CVSS 4.0
-
5.3 (MEDIUM)
מקור הציון: CNA
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-15/8/2026
- CWE
- CWE-863
מוצרים מושפעים
mycomplianceoffice: mycomplianceoffice
קישורים
- https://cert.pl/en/posts/2026/07/CVE-2026-53902 Third Party Advisory
- https://mco.mycomplianceoffice.com/ Product