CVE-2026-41034: Medium severity Onlyoffice DocumentServer vulnerability
ONLYOFFICE DocumentServer before 9.3.0 has an untrusted pointer dereference in XLS processing/conversion (via pictFmla.cbBufInCtlStm and other vectors), leading to an information leak and ASLR bypass.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41034?
CVE-2026-41034 is classified as a high severity vulnerability due to its potential to lead to information leaks and ASLR bypass.
How do I fix CVE-2026-41034?
To mitigate CVE-2026-41034, upgrade ONLYOFFICE DocumentServer to version 9.3.0 or later.
What security risks does CVE-2026-41034 pose?
CVE-2026-41034 can be exploited to cause an information leak and may bypass Address Space Layout Randomization (ASLR), compromising system security.
Which software versions are affected by CVE-2026-41034?
ONLYOFFICE DocumentServer versions prior to 9.3.0 are affected by CVE-2026-41034.
How does CVE-2026-41034 exploit untrusted pointer dereference?
CVE-2026-41034 exploits untrusted pointer dereference during XLS processing/conversion, affecting functions like pictFmla.cbBufInCtlStm.