Junglewise Threat Intelligence

CVE-2026-53908: MyComplianceOffice MCO user enumeration in authentication components

CVE-2026-53908 · Severity: info · CVSS 6.9 · Published 2026-07-01

Technologies: MyComplianceOffice MCO. Vendors: MyComplianceOffice.

Executive brief

MyComplianceOffice (MCO) is a compliance management platform used by financial services and insurance firms to manage regulatory obligations. A security flaw in the system's login and password recovery features allows unauthorized individuals to determine which email addresses and usernames have active accounts. This information can be used to facilitate targeted phishing attacks or credential guessing against specific employees.

Technical details

MyComplianceOffice (MCO) version 25.3.3.1 is vulnerable to user enumeration (CWE-204) within its authentication-related endpoints. The application returns distinguishable responses for valid versus invalid users during username reminder and password reset operations. This discrepancy allows a remote, unauthenticated attacker to programmatically verify the existence of specific usernames or email addresses. While the vendor was contacted, they did not respond, and it is currently unknown if a patch is available. The vulnerability was assigned a CVSS 4.0 score of 6.9 by CERT.PL.

Affected products

  • MyComplianceOffice MCO 25.3.3.1

Timeline

  • 2026-07-01: disclosed: Vulnerability disclosed by CERT.PL after unsuccessful vendor contact attempts.
  • 2026-07-01: advisory

References

Related threats