CVE-2026-53909: Arbitrary File Upload in MCO
MCO does not correctly validate types of uploaded files. File upload validation functionality relies only on client-side checks, which can be bypassed. An authorized, low-privileged attacker can upload files with arbitrary types to the server.
Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 25.3.3.1 but may also affect other versions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-53909?
The severity of CVE-2026-53909 is rated medium with a CVSS score of 5.3.
How do I fix CVE-2026-53909?
To fix CVE-2026-53909, ensure that server-side validation is implemented for uploaded files to prevent arbitrary file uploads.
What types of attacks can CVE-2026-53909 facilitate?
CVE-2026-53909 can facilitate attacks such as file execution and data exfiltration due to arbitrary file uploads.
Who is impacted by CVE-2026-53909?
Authorized users with low privileges on the MCO system can exploit CVE-2026-53909 due to inadequate file type validation.
When was CVE-2026-53909 published?
CVE-2026-53909 was published on July 1, 2026.