CVE-2026-41034: Ascensio ONLYOFFICE Documentserver

Medium severity, CVSS 5.0. EPSS: 0.3% chance of exploitation in the next 30 days.

ONLYOFFICE DocumentServer before 9.3.0 has an untrusted pointer dereference in XLS processing/conversion (via pictFmla.cbBufInCtlStm and other vectors), leading to an information leak and ASLR bypass.

Affected products

  • Ascensio ONLYOFFICE Documentserver: before 9.3.0 (fixed in 9.3.0)

Published 2026-04-16. Last modified 2026-06-17.