CVE-2026-41034

· NIST NVD ↗

ONLYOFFICE DocumentServer before 9.3.0 has an untrusted pointer dereference in XLS processing/conversion (via pictFmla.cbBufInCtlStm and other vectors), leading to an information leak and ASLR bypass.

MEDIUM
CVSS severity
5
CVSS base score
2026-04-16
Published

CWE codes

CWE-125

Sources