Executive brief
MyComplianceOffice (MCO) is a compliance management platform used by financial services and other regulated industries to manage risk and regulatory obligations. A security flaw in the software allows a standard user to bypass security checks and view sensitive administrative access control structures. This could allow an unauthorized person to see internal permission mappings and configuration details, potentially aiding in further attacks on the system.
Technical details
An incorrect authorization vulnerability (CWE-863) exists in the MyComplianceOffice (MCO) software within the '/customer/servlet/mco/webapi/admin-view-hierarchy/get-acl-tree-structure' endpoint. The application fails to validate if the requesting user has administrative privileges before returning the ACL tree structure. An authenticated, low-privileged attacker can send a direct request to this endpoint to retrieve sensitive permission mappings and internal configuration details. The vulnerability has been confirmed in version 25.3.3.1; however, because vendor contact attempts were unsuccessful, it is unknown if a patch is available or if other versions are affected.
Affected products
- MyComplianceOffice MCO 25.3.3.1
Timeline
- 2026-07-01: disclosed: Vulnerability disclosed by CERT Polska
- 2026-07-01: advisory: CVE-2026-53905 published