CVE-2026-2074 | O2OA up to 9.0.0 HTTP POST Request check xml external entity reference
A vulnerability, which was classified as problematic, has been found in O2OA up to 9.0.0. This impacts an unknown function of the file /x_program_center/jaxrs/mpweixin/check of the component HTTP POST Request Handler. The manipulation leads to xml external entity reference.
This vulnerability is traded as CVE-2026-2074. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.