CVE-2026-53907: Stored Cross‑Site Scripting in MCO

Published Jul 1, 2026
·
Updated

MCO is vulnerable to Stored Cross‑Site Scripting (XSS) via the application logo upload functionality. An attacker with the ability to change the application logo can upload a crafted SVG file containing malicious JavaScript code that is executed when the logo is rendered or opened.

Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 25.3.3.1 but may also affect other versions.

Affected Software

2 affected components
MCO=25.3.3.1
Mycomplianceoffice Mycomplianceoffice=25.3.3.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    Mitigate Stored XSS via the application logo upload functionality by restricting or disabling acceptance/rendering of user-supplied SVG logos (e.g., block SVG uploads and/or sanitize logo content to remove executable JavaScript before storing or rendering).

  2. Operational

    Review application logo upload history and remove/replace any logos that may have been uploaded as crafted SVGs containing malicious JavaScript, since the XSS is stored and will execute when the logo is rendered or opened.

Event History

Jul 1, 2026
CVE Published
via MITRE·11:58 AM
Data Sourced
via MITRE·11:58 AM
DescriptionWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-53907?

CVE-2026-53907 has a medium severity rating of 4.8 according to the CVSS.

2

How do I fix CVE-2026-53907?

To mitigate CVE-2026-53907, ensure that SVG file uploads are properly sanitized and validated before being processed.

3

What type of vulnerability is CVE-2026-53907?

CVE-2026-53907 is a Stored Cross-Site Scripting (XSS) vulnerability.

4

What impact can CVE-2026-53907 have?

CVE-2026-53907 can lead to execution of malicious JavaScript code when the crafted SVG logo is rendered.

5

Who is affected by CVE-2026-53907?

CVE-2026-53907 affects users of the MCO application who can modify the application logo.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203