CVE-2026-97179
Received Received - Intake

Information Disclosure in O2OA Cipher Connection Handler

Vulnerability report for CVE-2026-97179, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-24

Last updated on: 2026-09-24

Assigner: VulDB

Description

A security vulnerability has been detected in O2OA up to 9.5.3/10.0.2. This vulnerability affects the function list of the file o2server/x_base_core_project/src/main/java/com/x/base/core/project/connection/CipherConnectionAction.java of the component Cipher Connection Handler. Such manipulation of the argument fileUrl leads to information disclosure. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-24
Last Modified
2026-09-24
Generated
2026-09-24
AI Q&A
2026-09-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
o2oa o2oa to 9.5.3 (inc)
o2oa o2oa to 10.0.2 (inc)
o2oa o2oa From 9.5 (inc) to 10.0.2 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-97179 is a vulnerability in O2OA versions up to 9.5.3/10.0.2 affecting the CipherConnectionAction.java file. It allows information disclosure by manipulating the fileUrl argument, leading to remote attacks. The vendor did not respond to disclosure attempts.

Detection Guidance

Check O2OA server logs for suspicious POST requests to /x_general_assemble_control/jaxrs/excel/upload/with/url with external URLs in the fileUrl parameter. Monitor network traffic for outbound requests containing cipher tokens to unauthorized servers.

Impact Analysis

An attacker with a regular user account can exploit this to leak high-privilege cipher tokens via the /excel/upload/with/url endpoint. This token can then be used to access administrative functions, modify passwords, read sensitive data, and fully compromise the system.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating confidentiality requirements in GDPR and HIPAA. Full system compromise may result in non-compliance with data protection and security standards.

Mitigation Strategies

Immediately restrict access to the vulnerable endpoint by disabling /excel/upload/with/url. Implement strict URL allowlists for outbound connections. Isolate the O2OA server from external networks. Update to a patched version if available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-97179. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart