Cyber News / Article / Vulnerabilities in MyComplianceOffice MCO software

Vulnerabilities in MyComplianceOffice MCO software
CERT Polska has received a report about vulnerabilities in MyComplianceOffice MCO software and participated in coordination of their disclosure.
The vulnerabilityCVE-2026-53902: MCO does not properly enforce authorization checks in the/customer/servlet/mco/webapi/profile-sections/group-membershipendpoint. An authenticated user can modify their group membership without proper authorization checks, allowing privilege escalation. An attacker can add themselves to arbitrary groups by supplying a valid group ID, which can be obtained via other application functionalities (e.g./customer/servlet/mco/webapi/group/picker/groups), provided he has necessary permissions, or potentially inferred through brute-force techniques.
The vulnerabilityCVE-2026-53903: MCO is vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability in the/customer/servlet/mco/webapi/trading-document/fetchPdfStatementendpoint. The application does not properly validate whether an authenticated user is authorized to access a requested document, allowing direct retrieval based on a user-supplied identifier. An attacker can access trading documents belonging to other users by providing a valid document ID. Although exploitation requires guessing the identifier, predictable ID patterns enable feasible enumeration, leading to unauthorized disclosure of sensitive information.
The vulnerabilityCVE-2026-53904: MCO is vulnerable to Account Denial of Service due to improper implementation of password reset functionality. Each password reset request invalidates previously set password as well as previously issued temporary passwords, furthermore, password resets are not limited in any way. An attacker who provides victim's email and answer to their security question, can successfully initiate the reset process and continuously invalidate credentials, effectively locking the victim out of their account. Answering security questions has a limited number of tries which lowers the risk of this vulnerability.
The vulnerabilityCVE-2026-53905: MCO does not properly enforce authorization checks in the/customer/servlet/mco/webapi/admin-view-hierarchy/get-acl-tree-structureendpoint. An authenticated, low-privileged user can retrieve administrator access control structures without proper authorization checks. This may expose sensitive permission mappings and internal configuration details.
The vulnerabilityCVE-2026-53906: MCO is vulnerable to Path Disclosure and Path Traversal in file handling functionality related to data export and upload. Improper validation of thefilenameparameter allows writing files to arbitrary locations as well as indirect disclosure of absolute server paths through error messages.
The vulnerabilityCVE-2026-53907: MCO is vulnerable to Stored CrossâSite Scripting (XSS) via the application logo upload functionality. An attacker with the ability to change the application logo can upload a crafted SVG file containing malicious JavaScript code that is executed when the logo is rendered or opened.
The vulnerabilityCVE-2026-53908: MCO is vulnerable to User Enumeration through authentication-related functionalities. The application returns distinguishable responses for valid and invalid users during username reminder and password reset operations. An attacker can leverage these differences to enumerate valid usernames and email addresses.
The vulnerabilityCVE-2026-53909: MCO does not correctly validate types of uploaded files. File upload validation functionality relies only on client-side checks, which can be bypassed. An authorized, low-privileged attacker can upload files with arbitrary types to the server.
Because vendor contact attempts were unsuccessful, vulnerabilities have only been confirmed in version 25.3.3.1 but may also affect other versions.
We thank Hubert Decyusz from AFINE Team for the responsible vulnerability report.
Related articles
Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data
8 days ago
Top 10 Best Patch Management Software in 2026
2 days ago
September 2026 Patch Tuesday: Two Exploited Zero-Days and 113 Critical Vulnerabilities Among 972 CVEs
3 days ago
You might Also like

Hackers Target Claude, Cursor and Codex AI Agents to Steal Tokens and Prompt Histories

DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval

