CVE-2026-53905
HIGHMyComplianceOffice - Unauthorized Access to Administrator ACL View in MCO
Title source: ruleExploitation Summary
EIP tracks 1 public exploit for CVE-2026-53905. PoCs published by HermesNA-1.
AI-analyzed exploit summary This repository contains an auto-generated stub module for CVE-2026-53905, an authorization bypass vulnerability in MCO's /customer/servlet/mco/webapi/admin-view-hierarchy/get-acl-tree-structure endpoint. The code includes placeholder logic but lacks actual exploit implementation.
Description
MCO does not properly enforce authorization checks in the /customer/servlet/mco/webapi/admin-view-hierarchy/get-acl-tree-structure endpoint. An authenticated, low-privileged user can retrieve administrator access control structures without proper authorization checks. This may expose sensitive permission mappings and internal configuration details. Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 25.3.3.1 but may also affect other versions.
Exploits (1)
This repository contains an auto-generated stub module for CVE-2026-53905, an authorization bypass vulnerability in MCO's /customer/servlet/mco/webapi/admin-view-hierarchy/get-acl-tree-structure endpoint. The code includes placeholder logic but lacks actual exploit implementation.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N