MyComplianceOffice MCO是MyComplianceOffice公司的一款合规与风险管理软件。 MyComplianceOffice MCO 25.3.3.1版本存在授权问题漏洞,该漏洞源于对/customer/servlet/mco/webapi/trading-document/fetchPdfStatement端点的用户输入文档标识符验证不当,导致不安全的直接对象引用(IDOR),可能造成经过身份验证的攻击者访问其他用户的交易文档,导致敏感信息泄露。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| MyComplianceOffice | MCO | 25.3.3.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| MyComplianceOffice | MCO | 25.3.3.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-53902 | Privilege Escalation in MCO | |
| CVE-2026-53908 | User Enumeration in MCO | |
| CVE-2026-53907 | Stored Cross‑Site Scripting in MCO | |
| CVE-2026-53906 | Path Disclosure and Path Traversal in MCO | |
| CVE-2026-53904 | Account Denial of Service in MCO | |
| CVE-2026-53905 | Unauthorized Access to Administrator ACL View in MCO | |
| CVE-2026-53909 | Arbitrary File Upload in MCO |
No comments yet