Executive brief
MyComplianceOffice (MCO) is a compliance management platform used by financial services and insurance firms to manage regulatory obligations and trading documents. A security flaw allows an authenticated user to access the private trading documents and PDF statements of other users by manipulating document identifiers in the web address. This could lead to the unauthorized disclosure of sensitive financial information and personal data belonging to other customers.
Technical details
An Insecure Direct Object Reference (IDOR) vulnerability exists in the `/customer/servlet/mco/webapi/trading-document/fetchPdfStatement` endpoint of MyComplianceOffice (MCO). The application fails to perform adequate authorization checks to ensure that the requesting authenticated user has the rights to view a specific document. An attacker can supply a different document identifier to retrieve PDF statements belonging to other users. While exploitation requires knowledge of valid document IDs, the advisory notes that predictable ID patterns make enumeration feasible. The vulnerability is confirmed in version 25.3.3.1; vendor contact was unsuccessful, so patch status is unconfirmed.
Affected products
- MyComplianceOffice MCO 25.3.3.1
Timeline
- 2026-07-01: disclosed: Vulnerability disclosed by CERT Polska
- 2026-07-01: advisory