Vulnerabilities
Report: CVE-2026-41034 - ONLYOFFICE DocumentServer Untrusted Pointer Dereference Information Leak and ASL
CVE ID :CVE-2026-41034 Published : April 16, 2026, 6:06 a.m. | 43 minutes ago Description :ONLYOFFICE DocumentServer before 9.3.0 has an untrusted pointer dereference in XLS processing/conversion (via pictFmla.cbBufInCtlStm and other vectors), leading to an information leak and ASLR bypass. Severity: 5.0 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...