A security vulnerability has been detected in o2oa up to 10.0. This impacts the function syncFile of the file NodeAgent.java of the component NodeAgent. The manipulation leads to improper authorization. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitability is said to be difficult. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
CVE-2026-7292 is a medium-severity improper authorization vulnerability in o2oa up to version 10.0 affecting the syncFile function in NodeAgent.java component. Remote exploitation is possible but requires high attack complexity and difficult exploitability, though public exploits are available.
ثغرة في التفويض غير الصحيح تؤثر على وظيفة syncFile في مكون NodeAgent بتطبيق o2oa حتى الإصدار 10.0. يمكن استغلال الثغرة عن بعد لكن تتطلب تعقيداً عالياً في الهجوم وقابلية استغلال صعبة. تم الإفصاح العام عن الثغرة وقد يتم استخدام الاستغلالات المتاحة.
A medium-severity improper authorization flaw exists in o2oa versions up to 10.0 in the NodeAgent.java syncFile function. The vulnerability allows remote attacks with high complexity requirements and difficult exploitation, despite public disclosure of exploits.
Upgrade o2oa to version 10.1 or later immediately. Implement network-level access controls to restrict NodeAgent communications. Monitor and audit file synchronization activities. Apply principle of least privilege to service accounts running o2oa. Disable NodeAgent if not required for operations.
قم بترقية o2oa إلى الإصدار 10.1 أو أحدث فوراً. طبق عناصر تحكم الوصول على مستوى الشبكة لتقييد اتصالات NodeAgent. راقب وتدقق أنشطة مزامنة الملفات. طبق مبدأ أقل صلاحية على حسابات الخدمة التي تشغل o2oa. عطل NodeAgent إذا لم تكن مطلوبة للعمليات.