LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-53903

mycomplianceoffice · mycomplianceoffice

Published
CVSS8.1
Severityhigh
WeaknessCWE-639
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Description

MCO is vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability in the /customer/servlet/mco/webapi/trading-document/fetchPdfStatement endpoint. The application does not properly validate whether an authenticated user is authorized to access a requested document, allowing direct retrieval based on a user-supplied identifier. An attacker can access trading documents belonging to other users by providing a valid document ID. Although exploitation requires guessing the identifier, predictable ID patterns enable feasible enumeration, leading to unauthorized disclosure of sensitive information. Because vendor contact attempts were unsuccessful, the vulnerability has only been confi

References

← Back to the CVE Tracker

Our coverage of CVE-2026-53903

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-53903.