Multiple flaws found in MyComplianceOffice MCO
CERT Polska coordinated disclosure of eight vulnerabilities in MyComplianceOffice MCO, including privilege escalation, IDOR, and stored XSS bugs.
CERT Polska, working with researcher Hubert Decyusz of the AFINE Team, coordinated disclosure of eight vulnerabilities affecting MyComplianceOffice (MCO), a compliance management platform. The issues span authorization bypasses that let low-privileged users escalate group membership or view administrative ACL structures, an IDOR flaw allowing retrieval of other users' trading documents, a stored XSS via malicious SVG logo uploads, path traversal/disclosure in file export and upload functionality, weak file-type validation relying only on client-side checks, an account denial-of-service through unrestricted password reset abuse, and a user-enumeration weakness in authentication flows.
The vendor did not respond to disclosure attempts, so the vulnerabilities have only been confirmed against MCO version 25.3.3.1, though other versions may be affected. No patches or vendor advisories are referenced, and there is no indication of active exploitation in the wild — this is a coordinated vulnerability disclosure rather than a report of ongoing attacks. Organizations running MCO, which is commonly used for compliance and trading-document management in regulated industries, should assess exposure of the affected endpoints and restrict access pending vendor remediation.
Mentioned in this report
Source reporting: https://cert.pl/en/posts/2026/07/CVE-2026-53902
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free