Impact
MyComplianceOffice MCO’s /customer/servlet/mco/webapi/admin-view-hierarchy/get-acl-tree-structure endpoint fails to enforce proper authorization checks, allowing any authenticated user with low privileges to retrieve administrator access control structures. This exposure can reveal detailed permission mappings and internal configuration data, constituting a confidentiality disclosure. The weakness aligns with CWE‑863, a privilege escalation flaw, because it permits access to information normally reserved for administrators.
Affected Systems
The vulnerability has been confirmed in MyComplianceOffice MCO version 25.3.3.1. While other versions may be affected, no additional version information has been confirmed as of now.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is reported as < 1 %, suggesting that exploitation in the wild is unlikely. The vulnerability is not listed in the CISA KEV catalog. The attack would require an authenticated low‑privileged user to call the affected endpoint; no external exploitation pathway is described in the public data. An attacker can read administrative ACL structures, revealing detailed permission mappings and internal configuration details, which is a confidentiality disclosure. The weakness aligns with CWE‑863, a privilege escalation flaw.
OpenCVE Enrichment