Loading
A vulnerability was identified in O2OA up to 9.0.0. This impacts an unknown function of the file /x_program_center/jaxrs/mpweixin/check of the component HTTP POST Request Handler. The manipulation leads to xml external entity reference. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Use CWE-610, Zoneland vendor hub and O2oa product page to widen CVE-2026-2074 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-9737, CVE-2025-9736 and CVE-2025-9735 for nearby disclosures in the same product family.