CVE-2026-88405: Univer vulnerability
Published Sep 21, 2026
·Updated
A remote code execution (RCE) vulnerability in the RemoteRegisterFunctionService function (/remote/remote-register-function.service.ts) of Univer v1.0.0-alpha.2 allows attackers to execute arbitrary code via a crafted payload.
Affected Software
1 affected component
Univer=1.0.0-alpha.2
Event History
Sep 21, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:17 PM
Description
Frequently Asked Questions
1
Which deployments are identified as affected?
The affected software is Univer version 1.0.0-alpha.2. The vulnerable functionality is the RemoteRegisterFunctionService endpoint at /remote/remote-register-function.service.ts.
2
What input is associated with exploitation?
Exploitation is described as requiring a crafted payload sent to the RemoteRegisterFunctionService function. The available information does not specify authentication requirements or other prerequisites.