Vulnerability Description
MCO does not properly enforce authorization checks in the /customer/servlet/mco/webapi/profile-sections/group-membership endpoint. An authenticated user can modify their group membership without proper authorization checks, allowing privilege escalation. An attacker can add themselves to arbitrary groups by supplying a valid group ID, which can be obtained via other application functionalities (e.g. /customer/servlet/mco/webapi/group/picker/groups), provided he has necessary permissions, or potentially inferred through brute-force techniques. Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 25.3.3.1 but may also affect other versions.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mycomplianceoffice | Mycomplianceoffice | 25.3.3.1 |
Related Weaknesses (CWE)
References
- https://cert.pl/en/posts/2026/07/CVE-2026-53902Third Party Advisory
- https://mco.mycomplianceoffice.com/Product
FAQ
What is CVE-2026-53902?
CVE-2026-53902 is a vulnerability with a CVSS score of 6.5 (MEDIUM). MCO does not properly enforce authorization checks in the /customer/servlet/mco/webapi/profile-sections/group-membership endpoint. An authenticated user can modify their group membership without prope...
How severe is CVE-2026-53902?
CVE-2026-53902 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-53902?
Check the references section above for vendor advisories and patch information. Affected products include: Mycomplianceoffice Mycomplianceoffice.