CVE-2026-7292: o2oa NodeAgent NodeAgent.java syncFile improper authorization
A security vulnerability has been detected in o2oa up to 10.0. This impacts the function syncFile of the file NodeAgent.java of the component NodeAgent. The manipulation leads to improper authorization. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitability is said to be difficult. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7292?
CVE-2026-7292 is considered a high-severity vulnerability due to its potential for remote exploitation and improper authorization.
How do I fix CVE-2026-7292?
To fix CVE-2026-7292, upgrade o2oa to a version above 10.0 where the vulnerability has been addressed.
What component is affected by CVE-2026-7292?
CVE-2026-7292 affects the NodeAgent component within the o2oa software.
Can CVE-2026-7292 be exploited remotely?
Yes, CVE-2026-7292 can be exploited remotely, making it a significant risk for affected systems.
What type of attack does CVE-2026-7292 facilitate?
CVE-2026-7292 facilitates attacks through improper authorization, allowing unauthorized access to sensitive functions.