CVE-2022-22916

CRITICAL

Zoneland O2oa - Remote Code Execution

Title source: rule
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2022-22916. PoCs published by 0x7eTeam.

AI-analyzed exploit summary This repository provides a proof-of-concept for CVE-2022-22916, an RCE vulnerability in O2OA v6.4.7. The exploit involves authenticating as 'xadmin/o2', then creating and executing a malicious interface via the '/x_program_center/jaxrs/invoke' endpoint to achieve remote code execution.

Description

O2OA v6.4.7 was discovered to contain a remote code execution (RCE) vulnerability via /x_program_center/jaxrs/invoke.

Exploits (2)

nomisec WORKING POC 4 stars
by 0x7eTeam · poc
https://github.com/0x7eTeam/CVE-2022-22916

This repository provides a proof-of-concept for CVE-2022-22916, an RCE vulnerability in O2OA v6.4.7. The exploit involves authenticating as 'xadmin/o2', then creating and executing a malicious interface via the '/x_program_center/jaxrs/invoke' endpoint to achieve remote code execution.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: O2OA v6.4.7
Auth required
Prerequisites: Valid credentials for O2OA (xadmin/o2) · Network access to the target · Target running O2OA v6.4.7
devstral-2 · analyzed Feb 16, 2026 Full analysis →
inthewild WRITEUP
poc
https://github.com/aodsec/cve-2022-22916

The repository provides a detailed technical writeup for CVE-2022-22916, an RCE vulnerability in O2OA v6.4.7. It includes step-by-step instructions, HTTP request templates, and payload examples for exploiting the vulnerability via the `/x_program_center/jaxrs/invoke` endpoint.

Classification
Writeup 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: O2OA v6.4.7
Auth required
Prerequisites: Valid credentials (xadmin/o2) · Authorization token
devstral-2 · analyzed Feb 23, 2026 Full analysis →

References (2)

Core 2
Core References
Not Applicable x_refsource_misc
http://o2oa.com

Scores

CVSS v3 9.8
EPSS 0.9019
EPSS Percentile 99.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (1)
zoneland/o2oa 6.4.7
Published Feb 17, 2022
Tracked Since Feb 18, 2026