CVE-2026-67961
Received Received - Intake

Arbitrary Code Execution in O2OA via Invoke Sandbox Bypass

Vulnerability report for CVE-2026-67961, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-17

Last updated on: 2026-08-17

Assigner: MITRE

Description

An issue in O2OA v.10.0.2 allows a local attacker to execute arbitrary code via the the sandbox mechanism of the Invoke script execution.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-17
Last Modified
2026-08-17
Generated
2026-08-18
AI Q&A
2026-08-18
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in O2OA version 10.0.2 where a local attacker can exploit the sandbox mechanism of the Invoke script execution to run arbitrary code on the system.

Impact Analysis

A local attacker could gain control over the affected system by executing malicious code, potentially leading to data theft, system damage, or unauthorized access.

Mitigation Strategies

Update O2OA to a version that patches the sandbox mechanism vulnerability in the Invoke script execution. If no patch is available, disable or restrict access to the Invoke script execution feature until a fix is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-67961. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart