Description
A flaw has been found in O2OA up to 10.0.1-ce. This affects the function ActionUploadExcelWithUrl of the file /x_general_assemble_control/jaxrs/excel/upload/with/url of the component General Module. Executing a manipulation of the argument fileUrl can lead to server-side request forgery. The attack can be launched remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-10-05
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Server‑Side Request Forgery
Action: Patch
AI Analysis

Impact

The vulnerable endpoint ActionUploadExcelWithUrl in the General Module of O2OA allows an attacker to supply a crafted fileUrl argument that the server blindly fetches, resulting in a server‑side request forgery. This flaw can be exploited remotely and has published exploits, potentially allowing attackers to retrieve internal resources or interact with services that are otherwise inaccessible from the outside. The damage includes sensitive data exposure, potential privilege escalation, and indirect denial of service if internal resources are overloaded.

Affected Systems

All Deployments of the O2OA open‑source platform running versions up to and including 10.0.1‑ce are affected. The flaw resides in the /x_general_assemble_control/jaxrs/excel/upload/with/url endpoint of the General Module. Upgrades beyond 10.0.1‑ce or the removal of the vulnerable endpoint will eliminate the issue.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate impact. Although EPSS data is unavailable, the existence of a publicly available exploit and the remote nature of the attack elevate the risk. The vulnerability is not yet listed in the CISA KEV catalog. An attacker can mount the SSRF attack from a remote host, potentially accessing internal systems or services, provided the server can reach them. Because the flaw involves user‑supplied input, it is likely exploitable on any installation without additional hardening.

Generated by OpenCVE AI on October 5, 2026 at 22:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the O2OA platform to a non‑affected version, i.e., to a release that removes or secures the ActionUploadExcelWithUrl endpoint.
  • If an upgrade cannot be performed immediately, restrict the fileUrl parameter to a whitelist of trusted domains or enforce strict validation to accept only publicly reachable URLs, thereby preventing internal SSRF.
  • Harden network perimeter by blocking outbound requests from the application server to internal IP ranges and employing a WAF or security proxy to detect and block suspicious outbound traffic patterns typical of SSRF exploitation.

Generated by OpenCVE AI on October 5, 2026 at 22:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 21:15:00 +0000

Type Values Removed Values Added
Description A flaw has been found in O2OA up to 10.0.1-ce. This affects the function ActionUploadExcelWithUrl of the file /x_general_assemble_control/jaxrs/excel/upload/with/url of the component General Module. Executing a manipulation of the argument fileUrl can lead to server-side request forgery. The attack can be launched remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Title O2OA General url ActionUploadExcelWithUrl server-side request forgery
First Time appeared O2oa
O2oa o2oa
Weaknesses CWE-918
CPEs cpe:2.3:a:o2oa:o2oa:*:*:*:*:*:*:*:*
Vendors & Products O2oa
O2oa o2oa
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:P/I:N/A:N/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:C'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-05T20:45:13.878Z

Reserved: 2026-10-05T13:08:33.633Z

Link: CVE-2026-105438

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T21:16:34.297

Modified: 2026-10-05T21:16:34.297

Link: CVE-2026-105438

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T22:30:19Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)