{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-53902","assignerOrgId":"4bb8329e-dd38-46c1-aafb-9bf32bcb93c6","state":"PUBLISHED","assignerShortName":"CERT-PL","dateReserved":"2026-06-11T07:44:52.179Z","datePublished":"2026-07-01T11:58:31.205Z","dateUpdated":"2026-07-01T13:42:53.914Z"},"containers":{"cna":{"providerMetadata":{"orgId":"4bb8329e-dd38-46c1-aafb-9bf32bcb93c6","shortName":"CERT-PL","dateUpdated":"2026-07-01T11:58:31.205Z"},"title":"Privilege Escalation in MCO","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-266","description":"CWE-266 Incorrect Privilege Assignment","type":"CWE"}]},{"descriptions":[{"lang":"en","cweId":"CWE-863","description":"CWE-863 Incorrect Authorization","type":"CWE"}]}],"impacts":[{"capecId":"CAPEC-233","descriptions":[{"lang":"en","value":"CAPEC-233 Privilege Escalation"}]}],"affected":[{"vendor":"MyComplianceOffice","product":"MCO","versions":[{"status":"affected","version":"25.3.3.1","versionType":"custom"}],"defaultStatus":"unknown"}],"descriptions":[{"lang":"en","value":"MCO does not properly enforce authorization checks in the /customer/servlet/mco/webapi/profile-sections/group-membership endpoint. An authenticated user can modify their group membership without proper authorization checks, allowing privilege escalation.\nAn attacker can add themselves to arbitrary groups by supplying a valid group ID, which can be obtained via other application functionalities (e.g. /customer/servlet/mco/webapi/group/picker/groups), provided he has necessary permissions, or potentially inferred through brute-force techniques.\n\n\n\nBecause vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 25.3.3.1 but may also affect other versions.","supportingMedia":[{"type":"text/html","base64":false,"value":"MCO does not properly enforce authorization checks in the <i>/customer/servlet/mco/webapi/profile-sections/group-membership</i> endpoint. An authenticated user can modify their group membership without proper authorization checks, allowing privilege escalation.<br>An attacker can add themselves to arbitrary groups by supplying a valid group ID, which can be obtained via other application functionalities (e.g.&nbsp;<i>/customer/servlet/mco/webapi/group/picker/groups</i>), provided he has necessary permissions, or potentially inferred through brute-force techniques.<br><p><span><br>Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 25.3.3.1&nbsp;but may also affect other versions.</span></p>"}]}],"references":[{"url":"https://cert.pl/en/posts/2026/07/CVE-2026-53902","tags":["third-party-advisory"]},{"url":"https://mco.mycomplianceoffice.com/","tags":["product"]}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV4_0":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","subConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIGH","subIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED","version":"4.0","baseSeverity":"HIGH","baseScore":7.1,"vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N"}}],"credits":[{"lang":"en","value":"Hubert Decyusz (AFINE Team)","type":"finder"}],"source":{"discovery":"EXTERNAL"},"x_generator":{"engine":"Vulnogram 0.2.0"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-07-01T13:42:48.531051Z","id":"CVE-2026-53902","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-07-01T13:42:53.914Z"}}]}}