LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-53905

mycomplianceoffice · mycomplianceoffice

Published
CVSS7.1
Severityhigh
WeaknessCWE-863
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N

Description

MCO does not properly enforce authorization checks in the /customer/servlet/mco/webapi/admin-view-hierarchy/get-acl-tree-structure endpoint. An authenticated, low-privileged user can retrieve administrator access control structures without proper authorization checks. This may expose sensitive permission mappings and internal configuration details. Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 25.3.3.1 but may also affect other versions.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-53905

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-53905.