Sceawere
Vulnerability Detail
CVE-2026-105438UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
O2OA SSRF via fileUrl
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.3
- Creation Date
- 2h ago
- Vendor
- n/a
- Product
- O2OA
- Attack Type
- Server-Side Request Forgery
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
A flaw has been found in O2OA up to 10.0.1-ce. This affects the function ActionUploadExcelWithUrl of the file /x_general_assemble_control/jaxrs/excel/upload/with/url of the component General Module. Executing a manipulation of the argument fileUrl can lead to server-side request forgery. The attack can be launched remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.3",
"pubDate": "2026-10-05T21:16:34.297Z",
"pubdate": "2026-10-05T21:16:34.297Z",
"executiveSummary": "A Server-Side Request Forgery (SSRF) vulnerability exists in the O2OA platform, specifically within the General Module's Excel upload functionality.\nThe vulnerability resides in the ActionUploadExcelWithUrl function, which fails to adequately sanitize or validate the user-supplied fileUrl argument.\nThis flaw allows remote, unauthenticated attackers to force the O2OA server to make arbitrary HTTP requests to internal or external resources.\nThe impact includes the potential exposure of sensitive internal services, local network scanning, and unauthorized data exfiltration from behind the firewall.\nThe vulnerability is currently unpatched, and functional exploit code has been publicly disclosed, increasing the risk of active exploitation by malicious actors.\nOrganizations using O2OA versions up to 10.0.1-ce are at immediate risk and should prioritize isolating affected components or implementing network-level access controls.",
"technicalDetails": "The vulnerability is located in the /x_general_assemble_control/jaxrs/excel/upload/with/url endpoint within the O2OA General Module. The specific function responsible for processing the request is ActionUploadExcelWithUrl.\nThe root cause is an insecure implementation of a remote file fetching mechanism. The application accepts a user-controlled 'fileUrl' parameter, which is subsequently processed by the backend without verifying the target host, protocol, or destination network range.\nAn attacker can exploit this by sending a crafted HTTP request to the vulnerable endpoint, supplying a malicious URL in the 'fileUrl' parameter. When the O2OA server executes the request, it acts as a proxy, fetching content from the specified URL.\nBecause the server performs the request on behalf of the attacker, the server's internal identity and network location are used to interact with the target resource. This bypasses perimeter security controls, enabling the attacker to probe internal services that are not exposed to the public internet.\nThe attack flow proceeds as follows: 1) The attacker identifies the vulnerable endpoint; 2) The attacker crafts a request containing an internal IP address (e.g., http://127.0.0.1:8080 or internal service ports) within the fileUrl parameter; 3) The O2OA server processes the input and initiates a request to the target; 4) The server returns the result of the internal request, or the attacker uses the response headers and error messages to confirm service availability.\nThe impact of a successful SSRF attack in this context is significant. It allows an attacker to perform internal reconnaissance, identify active services on the local host or internal network, interact with cloud provider metadata services (e.g., 169.254.169.254), or potentially exploit internal applications that rely on trust-based authentication. Given that the project maintainers have not yet provided a patch, the risk remains critical for all deployments within the affected version range."
}