CVE-2026-3422

CRITICAL WAF: Medium
CVSS 9.8 Published: 2026-03-02
CWE-502

U-Office Force developed by e-Excellence has a Insecure Deserialization vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the server by sending maliciously crafted serialized content.

WAF Coverage Analysis

Insecure Deserialization Medium WAF Coverage

OWASP: A08:2021 Software and Data Integrity Failures

944xxx - Java Attack

Affected Software

VendorProductVersion
edetwu-office_forceup to 29.50
edetwu-office_force29.50

References

Back to CVE Database