CVE-2026-41030: Ascensio ONLYOFFICE Desktopeditors

Medium severity, CVSS 6.2. EPSS: 0.2% chance of exploitation in the next 30 days.

In ONLYOFFICE DesktopEditors before 9.3.0, the update service allows attackers to perform actions on files with SYSTEM privileges.

Affected products

  • Ascensio ONLYOFFICE Desktopeditors: before 9.3.0 (fixed in 9.3.0)

Published 2026-04-16. Last modified 2026-06-17.