CVE-2026-88404: Univer Univer vulnerability
Published Sep 21, 2026
·Updated
A remote code execution (RCE) vulnerability in the UniscriptExecutionService.execute() function (/services/script-execution.service.ts) of Univer v1.0.0-alpha.2 allows attackers to execute arbitrary code via a crafted payload.
Affected Software
1 affected component
Univer Univer=1.0.0-alpha.2
Event History
Sep 21, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:17 PM
Description
Frequently Asked Questions
1
Which releases are known to be affected?
The available information identifies Univer v1.0.0-alpha.2 as affected. It does not state whether earlier, later, or patched releases are affected.
2
Does exploitation require authentication or specific permissions?
The available information states that exploitation is remote and uses a crafted payload, but it does not specify any authentication, authorization, or permission requirements.