Skip to main content
Vulnerability Database/CVE-2026-105438

CVE-2026-105438: O2OA SSRF Vulnerability in Excel Upload

CVE-2026-105438 is a server-side request forgery vulnerability in O2OA up to version 10.0.1-ce that allows remote attackers to manipulate file upload requests. This article covers technical details, affected versions, and mitigation steps.

Published:

CVE-2026-105438 Overview

CVE-2026-105438 is a Server-Side Request Forgery (SSRF) vulnerability affecting O2OA versions up to 10.0.1-ce. The flaw resides in the ActionUploadExcelWithUrl function within the /x_general_assemble_control/jaxrs/excel/upload/with/url endpoint of the General Module. An authenticated remote attacker can manipulate the fileUrl argument to coerce the server into issuing arbitrary HTTP requests. The vulnerability is classified under CWE-918. According to the advisory, the exploit has been published and the upstream project was notified through an issue report but has not responded.

Critical Impact

Authenticated attackers can abuse the O2OA Excel upload endpoint to send crafted HTTP requests from the server, enabling internal network reconnaissance, metadata service access, and interaction with otherwise unreachable services.

Affected Products

  • O2OA up to and including version 10.0.1-ce
  • Component: General Module
  • Endpoint: /x_general_assemble_control/jaxrs/excel/upload/with/url

Discovery Timeline

  • 2026-10-05 - CVE-2026-105438 published to NVD
  • 2026-10-06 - Last updated in NVD database

Technical Details for CVE-2026-105438

Vulnerability Analysis

The vulnerability sits in the ActionUploadExcelWithUrl handler, which accepts a user-supplied fileUrl parameter and fetches content from the specified URL to process as an Excel file. The handler does not validate or restrict the URL target before issuing the outbound request. An authenticated attacker with low privileges can submit URLs pointing to internal network resources, loopback addresses, or cloud instance metadata endpoints. The server performs the request on behalf of the attacker, returning or leaking information about internal services. According to the published advisory, exploitation requires network access and valid credentials but no user interaction.

Root Cause

The root cause is missing URL validation in the ActionUploadExcelWithUrl function. The code treats the fileUrl parameter as trusted input and passes it directly to an HTTP client without allowlist checks, scheme restrictions, or destination filtering. This classic SSRF pattern [CWE-918] allows attackers to pivot server-side HTTP capabilities against internal infrastructure.

Attack Vector

The attack is launched remotely over the network against the exposed REST endpoint. An authenticated user sends a POST or GET request to /x_general_assemble_control/jaxrs/excel/upload/with/url with a crafted fileUrl value referencing an internal host such as http://127.0.0.1:admin-port or a cloud metadata service like http://169.254.169.254/latest/meta-data/. The O2OA server then fetches the target and processes or returns the response. See the GitHub O2OA Issue #210 and VulDB CVE-2026-105438 entries for additional technical context.

Detection Methods for CVE-2026-105438

Indicators of Compromise

  • HTTP requests to /x_general_assemble_control/jaxrs/excel/upload/with/url containing fileUrl parameters that reference private IP ranges (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16), loopback addresses, or link-local addresses such as 169.254.169.254.
  • Outbound HTTP connections initiated by the O2OA Java process to unexpected internal hosts or cloud metadata endpoints.
  • Application logs showing Excel upload activity against hosts that do not host Excel resources.

Detection Strategies

  • Deploy web application firewall (WAF) rules that inspect the fileUrl parameter for internal address literals and non-HTTP(S) schemes such as file://, gopher://, or dict://.
  • Correlate authenticated session activity on the vulnerable endpoint with new outbound destinations from the O2OA host.
  • Monitor cloud instance metadata service (IMDS) access logs for requests originating from the O2OA workload.

Monitoring Recommendations

  • Enable verbose access logging on the O2OA REST layer and forward logs to a central SIEM for anomaly analysis.
  • Alert on repeated 4xx or 5xx responses from the /excel/upload/with/url endpoint, which may indicate probing.
  • Track egress traffic from application servers and baseline expected destinations to surface SSRF-driven pivots.

How to Mitigate CVE-2026-105438

Immediate Actions Required

  • Restrict network access to the /x_general_assemble_control/jaxrs/excel/upload/with/url endpoint to trusted administrative networks only.
  • Enforce strict egress filtering on the O2OA server to block connections to internal subnets, loopback, and cloud metadata addresses.
  • Audit O2OA accounts and revoke unused credentials to limit the pool of users who can invoke the vulnerable function.

Patch Information

No vendor patch is available at the time of publication. According to the advisory, the O2OA project was informed through GitHub O2OA Issue #210 but has not responded. Monitor the GitHub O2OA Repository for a fixed release and apply updates as soon as they are published.

Workarounds

  • Place O2OA behind a reverse proxy that strips or rewrites requests to the vulnerable upload endpoint until a patch is released.
  • Deploy an outbound proxy with an allowlist of permitted file-hosting destinations and force the application through it.
  • Use host-based firewall rules on the O2OA server to deny traffic to RFC1918 ranges and 169.254.169.254 from the Java process.
bash
# Example iptables rules to block SSRF targets from the O2OA host
iptables -A OUTPUT -m owner --uid-owner o2oa -d 169.254.169.254 -j REJECT
iptables -A OUTPUT -m owner --uid-owner o2oa -d 127.0.0.0/8 -j REJECT
iptables -A OUTPUT -m owner --uid-owner o2oa -d 10.0.0.0/8 -j REJECT
iptables -A OUTPUT -m owner --uid-owner o2oa -d 172.16.0.0/12 -j REJECT
iptables -A OUTPUT -m owner --uid-owner o2oa -d 192.168.0.0/16 -j REJECT

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.