Executive brief
MyComplianceOffice (MCO) is a compliance management platform used by financial services and insurance firms to automate regulatory oversight and risk management. A security vulnerability in the software's file handling system allows high-privileged users to manipulate file paths during data exports and uploads. This could lead to the unauthorized writing of files to sensitive server locations or the exposure of internal server directory structures through error messages, potentially compromising the integrity of the hosting environment.
Technical details
A path traversal and path disclosure vulnerability exists in MyComplianceOffice (MCO) version 25.3.3.1. The flaw is located in the file handling functionality related to data export and upload, where the application fails to properly validate the 'filename' parameter. An authenticated attacker with high privileges can exploit this to perform directory traversal, enabling the writing of files to arbitrary locations on the server filesystem. Additionally, improper error handling during these operations can leak absolute server paths to the attacker. While the vendor has not confirmed the fix, the vulnerability was disclosed by CERT Polska after unsuccessful contact attempts.
Affected products
- MyComplianceOffice MCO 25.3.3.1
Timeline
- 2026-07-01: advisory: Advisory published by CERT Polska
- 2026-07-01: disclosed: NVD publication date