CVE-2026-3422

Severity CVSS v4.0:
CRITICAL
Type:
CWE-502 Deserialization of Untrusted Dat
Publication date:
02/03/2026
Last modified:
09/03/2026

Description

U-Office Force developed by e-Excellence has a Insecure Deserialization vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the server by sending maliciously crafted serialized content.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:edetw:u-office_force:*:*:*:*:*:*:*:* 29.50 (excluding)
cpe:2.3:a:edetw:u-office_force:29.50:-:*:*:*:*:*:*