What is CVE-2026-67961?
This vulnerability in O2OA v.10.0.2 arises from the sandbox mechanism in Invoke script execution, allowing a local attacker to execute arbitrary code. It enables escaping the sandbox environment to perform malicious operations on affected systems. Users are advised to immediately update O2OA to the latest version.
Azərbaycanca: Bu zəiflik O2OA v.10.0.2 versiyasında Invoke skript icrasının sandbox mexanizmində yaranır və lokal hücumçuya ixtiyari kod icra etməyə imkan verir. Təsirə məruz qalan sistemlərdə sandbox mühitindən kənara çıxaraq zərərli əməliyyatlar həyata keçirilə bilər. İstifadəçilərə dərhal O2OA-nı ən son versiyaya yeniləmək tövsiyə olunur.
FAQ2
Which software is affected by CVE-2026-67961?
This vulnerability affects version 10.0.2 of O2OA.
How can one protect against CVE-2026-67961?
Users are advised to immediately update O2OA to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.