LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-53906

mycomplianceoffice · mycomplianceoffice

Published
CVSS8.2
Severityhigh
WeaknessCWE-22
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N

Description

MCO is vulnerable to Path Disclosure and Path Traversal in file handling functionality related to data export and upload. Improper validation of the filename parameter allows writing files to arbitrary locations as well as indirect disclosure of absolute server paths through error messages. Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 25.3.3.1 but may also affect other versions.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-53906

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-53906.