Impact
The vulnerability lies in MCO's /customer/servlet/mco/webapi/admin-view-hierarchy/get-acl-tree-structure endpoint, which fails to enforce proper authorization checks. An authenticated user with low privileges can retrieve administrative ACL structures that are normally restricted to administrators. This leakage exposes detailed permission mappings and internal configuration details, constituting a confidentiality disclosure. The weakness aligns with CWE‑863, a privilege escalation flaw, because it permits access to information reserved for administrators.
Affected Systems
The issue has been confirmed in MyComplianceOffice MCO version 25.3.3.1. No additional affected versions have been explicitly confirmed, though the vulnerability may also impact other releases of MCO.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score of < 1 % suggests that exploitation in the wild is unlikely. The vulnerability is not listed in CISA's KEV catalog. An attacker must be an authenticated low‑privileged user to call the vulnerable endpoint, and the attack would be carried out over the web API. No external exploitation pathway is described. The impact is a confidentiality disclosure of administrative ACL structures.
OpenCVE Enrichment