Impact
MCO fails to enforce proper authorization checks on the /customer/servlet/mco/webapi/profile‑sections/group‑membership endpoint, allowing an authenticated user to modify their own group membership without proper verification. By submitting a valid group identifier—obtained through the group‑picker API or guessed—an attacker can add themselves to any group, thereby gaining elevated privileges. The flaw is rooted in missing authorization controls (CWE-266) and improper access control via identifiers (CWE-863).
Affected Systems
The issue has been confirmed in MyComplianceOffice MCO version 25.3.3.1. Vendor warnings indicate that other releases may also be impacted, but no official confirmation yet exists and no patch has been released due to unsuccessful vendor contact attempts.
Risk and Exploitability
The CVSS score is 7.1, indicating a medium‑high severity exposure. The EPSS score is below 1%, reflecting a very low but nonzero likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. An attacker must obtain or guess a valid group ID, which can be sourced via the group‑picker endpoint or through brute‑force enumeration. With an authenticated session, the vulnerability can be exploited to elevate privileges.
OpenCVE Enrichment