Executive brief
MyComplianceOffice (MCO) is a compliance management platform used by financial services and insurance firms to automate regulatory oversight. A security flaw in the application's logo upload feature allows an attacker with administrative privileges to upload a malicious image file. If this file is viewed by other users, it could allow the attacker to hijack their sessions or perform unauthorized actions within the platform.
Technical details
A Stored Cross-Site Scripting (XSS) vulnerability exists in MyComplianceOffice (MCO) version 25.3.3.1. The flaw is located in the application logo upload functionality, which fails to properly sanitize uploaded SVG files. An authenticated attacker with permissions to modify the application logo can upload a crafted SVG containing malicious JavaScript. This script executes in the context of any user who renders or opens the logo file. While exploitation requires high privileges (PR:H) and some user interaction (UI:P), it can lead to session hijacking or unauthorized data access within the web interface. No patch is currently confirmed as vendor contact attempts were unsuccessful.
Affected products
- MyComplianceOffice MCO 25.3.3.1
Timeline
- 2026-07-01: advisory: Advisory published by CERT Polska
- 2026-07-01: disclosed: CVE-2026-53907 published to NVD