CVE-2026-41030: Medium severity Onlyoffice ONLYOFFICE DesktopEditors vulnerability
Published Apr 16, 2026
·Updated
In ONLYOFFICE DesktopEditors before 9.3.0, the update service allows attackers to perform actions on files with SYSTEM privileges.
Affected Software
1 affected component
Onlyoffice ONLYOFFICE DesktopEditors<9.3.0
Event History
Apr 16, 2026
CVE Published
via MITRE·05:51 AM
Data Sourced
via MITRE·05:51 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-41030?
CVE-2026-41030 is a high severity vulnerability that allows attackers to perform actions on files with SYSTEM privileges.
2
How do I fix CVE-2026-41030?
The only way to fix CVE-2026-41030 is to update ONLYOFFICE DesktopEditors to version 9.3.0 or later.
3
What are the potential impacts of CVE-2026-41030?
CVE-2026-41030 can potentially allow unauthorized modifications or access to sensitive files due to elevated privileges.
4
Who is affected by CVE-2026-41030?
CVE-2026-41030 affects all users of ONLYOFFICE DesktopEditors versions prior to 9.3.0.
5
Is there a workaround for CVE-2026-41030?
There are no known effective workarounds for CVE-2026-41030; updating the software is recommended as the only mitigation.