CVE-2026-97179 | O2OA up to 9.5.3/10.0.2 Cipher Connection CipherConnectionAction.java list fileUrl information disclosure
A vulnerability was found in O2OA up to 9.5.3/10.0.2 and classified as problematic. This vulnerability affects the function list of the file o2server/x_base_core_project/src/main/java/com/x/base/core/project/connection/CipherConnectionAction.java of the component Cipher Connection Handler. Such manipulation of the argument fileUrl leads to information disclosure.
This vulnerability is referenced as CVE-2026-97179. It is possible to launch the attack remotely. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More