CVE-2026-67961

7.8

O2OA · O2OA

A sandbox bypass vulnerability in O2OA v.10.0.2 allows local attackers to execute arbitrary code via the Invoke script mechanism.

Executive summary

O2OA v.10.0.2 contains a critical sandbox bypass vulnerability that permits local attackers to achieve arbitrary code execution on the hosting infrastructure.

Vulnerability

The application fails to properly enforce security boundaries within the Invoke script execution sandbox. A local, authenticated attacker can leverage this weakness to inject malicious payloads, effectively bypassing intended restrictions and gaining unauthorized code execution capabilities.

Business impact

This vulnerability carries a CVSS score of 7.8, indicating a high severity risk. Successful exploitation allows an attacker to compromise the integrity and availability of the host system, potentially leading to unauthorized data access or complete infrastructure control. Given the potential for lateral movement once code execution is achieved, this flaw poses a significant risk to the security of the internal network.

Remediation

Immediate Action: Contact the vendor immediately to obtain the latest security update or patch for O2OA v.10.0.2, as no public patch version is currently identified.

Proactive Monitoring: Review system access logs for unusual script execution patterns or attempts to invoke administrative functions by unauthorized local accounts.

Compensating Controls: Restrict local system access to authorized personnel only, and implement strict least-privilege policies for accounts interacting with the O2OA application environment.

Exploitation status

Public Exploit Available: No (no confirmed public exploit identified).

Analyst recommendation

Organizations running O2OA v.10.0.2 should treat this as a high-priority issue. While no immediate patch is listed, administrators must limit local access to the affected servers and monitor for suspicious behavior until a vendor-supplied update is applied.