PT-2026-35752 · O2Oa · O2Oa

Larlarua

·

Published

2026-04-28

·

Updated

2026-04-28

·

CVE-2026-7291

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions o2oa versions prior to 10.0
Description A flaw in the URL Fetching component allows for remote server-side request forgery (SSRF), which occurs when a server is tricked into making requests to an unintended location. This issue exists within the FileAction() function of the FileAction.java file and is triggered by manipulating the fileUrl argument.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the FileAction() function or the URL Fetching component to minimize the risk of exploitation.

Exploit

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-7291

Affected Products

O2Oa