S.MANE//SEC × AI OPS
--:--:-- UTCHARDENED
← BACK TO WIRE
CVEHIGH2026-07-08

CVE-2026-53905: high vulnerability (CVSS 7.1)

CVE-2026-53905 allows low-privileged users to access admin ACL structures via the /admin-view-hierarchy/get-acl-tree-structure endpoint in MCO v25.3.3.1, exposing sensitive permissions and configurations. Vendor contact attempts failed; other versions may be vulnerable.

// OPERATOR NOTE — S.MANE

Prioritize blocking or monitoring access to the vulnerable endpoint. Consider implementing custom authorization checks if patching is unavailable. The lack of vendor response heightens urgency for mitigation.

CVE-2026-53905 is a high-severity vulnerability (CVSS 7.1) affecting MCO's authorization mechanisms. It allows authenticated, low-privileged users to retrieve sensitive admin ACL structures via the /customer/servlet/mco/webapi/admin-view-hierarchy/get-acl-tree-structure endpoint.

The exposure of permission mappings and internal configurations could enable privilege escalation or reconnaissance for lateral movement within the system. Vendor contact attempts have been unsuccessful, and only version 25.3.3.1 has been confirmed vulnerable so far.

Organizations using MCO should immediately restrict access to the affected endpoint and audit user permissions. If patching is unavailable, custom safeguards or WAF rules should be implemented to mitigate exploitation risks.

#CVE-2026-53905