High severity7.1NVD Advisory· Published Jul 1, 2026· Updated Jul 6, 2026
CVE-2026-53905
CVE-2026-53905
Description
MCO does not properly enforce authorization checks in the /customer/servlet/mco/webapi/admin-view-hierarchy/get-acl-tree-structure endpoint. An authenticated, low-privileged user can retrieve administrator access control structures without proper authorization checks. This may expose sensitive permission mappings and internal configuration details.
Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 25.3.3.1 but may also affect other versions.
Affected products
2- cpe:2.3:a:mycomplianceoffice:mycomplianceoffice:25.3.3.1:*:*:*:*:*:*:*
- Range: 25.3.3.1
Patches
Vulnerability mechanics
References
2- cert.pl/en/posts/2026/07/CVE-2026-53902nvdThird Party Advisory
- mco.mycomplianceoffice.comnvdProduct
News mentions
0No linked articles in our index yet.