Impact
MCO exposes a direct identifier for trading documents in the /customer/servlet/mco/webapi/trading-document/fetchPdfStatement endpoint that is not validated against the authenticated user's ownership. An attacker who can authenticate to the system can supply any document identifier and retrieve that document. While the attacker must guess or enumerate valid identifiers, predictable ID patterns make enumeration feasible, resulting in confidential financial information being disclosed.
Affected Systems
MyComplianceOffice MCO version 25.3.3.1 is confirmed to be affected; other releases that expose the same endpoint without an ownership check may also be vulnerable.
Risk and Exploitability
The vulnerability has a CVSS score of 5.3, indicating a moderate impact. The EPSS score is less than 1%, meaning the likelihood of exploitation is very low and it is not listed in the CISA KEV catalog. However, because exploitation requires the attacker to be authenticated and to enumerate document IDs, the risk is increased for environments with many users and weak monitoring, but overall it remains moderate.
OpenCVE Enrichment