Untrusted Pointer Dereference in ONLYOFFICE DocumentServer
CVE-2026-41034
5MEDIUM
What is CVE-2026-41034?
The vulnerability discovered in ONLYOFFICE DocumentServer prior to version 9.3.0 involves an untrusted pointer dereference during the XLS processing and conversion. This issue can be exploited through specific vectors, including pictFmla.cbBufInCtlStm, leading to potential information leaks and an undesired bypass of address space layout randomization (ASLR), compromising system integrity.
Affected Version(s)
ONLYOFFICE DocumentServer 0 < 9.3.0
