CVE-2026-2074: O2OA HTTP POST Request check xml external entity reference
A vulnerability was identified in O2OA up to 9.0.0. This impacts an unknown function of the file /xprogramcenter/jaxrs/mpweixin/check of the component HTTP POST Request Handler. The manipulation leads to xml external entity reference. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2074?
The severity of CVE-2026-2074 is classified as high due to the potential for unauthorized access and information disclosure.
How do I fix CVE-2026-2074?
To fix CVE-2026-2074, update O2OA to a version beyond 9.0.0 to mitigate the XML external entity reference vulnerability.
What components are affected by CVE-2026-2074?
CVE-2026-2074 affects the HTTP POST Request Handler component of O2OA up to version 9.0.0.
What type of vulnerability is CVE-2026-2074?
CVE-2026-2074 is an XML External Entity (XXE) vulnerability, which can be exploited through crafted XML input.
What impact does CVE-2026-2074 have on users?
The impact of CVE-2026-2074 can lead to unauthorized data access and potential exposure of sensitive information to attackers.