By vendor

Mycomplianceoffice vulnerabilities

Known CVEs affecting Mycomplianceoffice products, prioritized by severity, with SEC.co remediation and detection guidance.

8 published vulnerabilities

  • CVE-2026-53906HIGH 8.2

    MCO (MyComplianceOffice) contains a vulnerability in its file handling system that allows attackers to write files to unintended locations on the server and discover sensitive path information through error messages. The flaw stems from inadequate validation of filenames during data export and upload operations. An attacker with network access can exploit this without authentication to alter file placement or gather reconnaissance data about the server's directory structure.

  • CVE-2026-53903HIGH 8.1

    MCO (MyComplianceOffice) contains a critical authorization flaw that allows authenticated users to view trading documents belonging to other customers. An attacker with valid login credentials can request documents from different users by manipulating document identifiers in the web API endpoint, potentially exposing sensitive financial and compliance records. While the attack requires knowing or guessing valid document IDs, the predictable nature of these identifiers makes systematic enumeration feasible.

  • CVE-2026-53904HIGH 7.1

    MCO (mycomplianceoffice) contains a flaw in its password reset mechanism that allows attackers to repeatedly lock victims out of their accounts. If an attacker knows a victim's email address and can answer their security question, they can trigger unlimited password resets that continuously invalidate all active credentials—including both regular passwords and temporary reset tokens. This turns a feature meant to help users regain access into a weapon for account denial of service. The attack requires one successful security question answer, though MCO does limit the number of wrong attempts.

  • CVE-2026-53905HIGH 7.1

    A security vulnerability in MyComplianceOffice (MCO) allows authenticated users with basic privileges to access sensitive administrator permission structures they shouldn't be able to see. The vulnerability exists in a specific web endpoint that manages access control hierarchies. When exploited, it exposes internal security configuration details that could be leveraged by an attacker to understand the system's administrative structure and potentially plan further attacks. The issue was identified in version 25.3.3.1, though other versions may be affected as well.

  • CVE-2026-53902MEDIUM 6.5

    MCO (MyComplianceOffice) contains a flaw that allows authenticated users to bypass authorization controls and add themselves to groups they shouldn't access. An attacker with valid login credentials could escalate their privileges by joining arbitrary groups, potentially gaining unauthorized access to sensitive functions or data restricted to those groups. The vulnerability requires authentication and was confirmed in version 25.3.3.1, though other versions may be affected.

  • CVE-2026-53909MEDIUM 6.5

    MCO (MyComplianceOffice) contains a file upload vulnerability where the application fails to validate file types on the server side. An attacker with legitimate user credentials can bypass client-side restrictions and upload arbitrary file types to the system. This could allow malicious files such as executables, scripts, or other dangerous content to be stored on the server, potentially leading to further compromise depending on how uploaded files are processed or served.

  • CVE-2026-53907MEDIUM 5.4

    MCO (My Compliance Office) contains a stored cross-site scripting vulnerability in its logo upload feature. An authenticated attacker can upload a specially crafted SVG file containing malicious JavaScript that executes when other users view or render the logo. The vulnerability requires user interaction and authenticated access, but once exploited, affects all users who load the compromised logo, making it a persistent threat within the application.

  • CVE-2026-53908MEDIUM 4.3

    MCO (MyComplianceOffice) contains a user enumeration vulnerability in its authentication workflows. When users attempt to reset passwords or retrieve usernames, the application responds differently depending on whether an account exists. An attacker with login access can exploit these timing or content differences to systematically discover valid usernames and associated email addresses—useful for follow-up social engineering, credential stuffing, or targeted account takeover attempts. The vendor has not been successfully contacted to confirm scope beyond version 25.3.3.1.