ONLYOFFICE DocumentServer before 9.3.0 has an untrusted pointer dereference in XLS processing/conversion (via pictFmla.cbBufInCtlStm and other vectors), leading to an information leak and ASLR bypass.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 16 Apr 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Untrusted Pointer Dereference in ONLYOFFICE DocumentServer XLS Processing Causes Information Leak and ASLR Bypass | |
| First Time appeared |
Onlyoffice
Onlyoffice document Server |
|
| Vendors & Products |
Onlyoffice
Onlyoffice document Server |
Thu, 16 Apr 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ONLYOFFICE DocumentServer before 9.3.0 has an untrusted pointer dereference in XLS processing/conversion (via pictFmla.cbBufInCtlStm and other vectors), leading to an information leak and ASLR bypass. | |
| Weaknesses | CWE-125 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-04-16T06:13:45.134Z
Reserved: 2026-04-16T06:06:44.178Z
Link: CVE-2026-41034
No data.
Status : Received
Published: 2026-04-16T07:16:30.843
Modified: 2026-04-16T07:16:30.843
Link: CVE-2026-41034
No data.
OpenCVE Enrichment
Updated: 2026-04-16T09:00:05Z
Weaknesses