---
id: CVE-2026-105438
title: A flaw has been found in O2OA up to 10.0.1-ce
summary: >-
  A flaw has been found in O2OA up to 10.0.1-ce. This affects the function
  ActionUploadExcelWithUrl of the file
  /x_general_assemble_control/jaxrs/excel/upload/with/url of the component
  General Module. Executing a manipulation of the argume…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-918
product: O2OA
affected:
  - O2OA 10.0.1-ce
published: '2026-10-05'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T21:16:34.297'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105438'
references:
  - url: 'https://github.com/o2oa/o2oa/'
    label: cna@vuldb.com
  - url: 'https://github.com/o2oa/o2oa/issues/210'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-105438'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/983598'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/413603'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/413603/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-05T21:34:25.112Z'
---

## Overview

A flaw has been found in O2OA up to 10.0.1-ce. This affects the function ActionUploadExcelWithUrl of the file /x_general_assemble_control/jaxrs/excel/upload/with/url of the component General Module. Executing a manipulation of the argument fileUrl can lead to server-side request forgery. The attack can be launched remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
