A vulnerability, which was classified as problematic, has been found in O2OA 10.0.2. Affected is an unknown function of the component Sandbox. The manipulation leads to improper privilege management.

This vulnerability is documented as CVE-2026-67961. The attack needs to be performed locally. There is not any exploit available.