Untrusted Pointer Dereference in ONLYOFFICE DocumentServer
CVE-2026-41034

5MEDIUM

Key Information:

Vendor

Ascensio

Vendor
CVE Published:
16 April 2026

What is CVE-2026-41034?

The vulnerability discovered in ONLYOFFICE DocumentServer prior to version 9.3.0 involves an untrusted pointer dereference during the XLS processing and conversion. This issue can be exploited through specific vectors, including pictFmla.cbBufInCtlStm, leading to potential information leaks and an undesired bypass of address space layout randomization (ASLR), compromising system integrity.

Affected Version(s)

ONLYOFFICE DocumentServer 0 < 9.3.0

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.