CVE-2026-3422

U-Office Force developed by e-Excellence has a Insecure Deserialization vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the server by sending maliciously crafted serialized content.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:edetw:u-office_force:*:*:*:*:*:*:*:*
cpe:2.3:a:edetw:u-office_force:29.50:-:*:*:*:*:*:*

History

09 Mar 2026, 14:16

Type Values Removed Values Added
First Time Edetw
Edetw u-office Force
References () https://www.twcert.org.tw/en/cp-139-10743-9a952-2.html - () https://www.twcert.org.tw/en/cp-139-10743-9a952-2.html - Third Party Advisory
References () https://www.twcert.org.tw/tw/cp-132-10742-45b13-1.html - () https://www.twcert.org.tw/tw/cp-132-10742-45b13-1.html - Third Party Advisory
CPE cpe:2.3:a:edetw:u-office_force:29.50:-:*:*:*:*:*:*
cpe:2.3:a:edetw:u-office_force:*:*:*:*:*:*:*:*

02 Mar 2026, 20:29

Type Values Removed Values Added
Summary
  • (es) U-Office Force desarrollado por e-Excellence tiene una vulnerabilidad de deserialización insegura, que permite a atacantes remotos no autenticados ejecutar código arbitrario en el servidor mediante el envío de contenido serializado maliciosamente manipulado.

02 Mar 2026, 07:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-02 07:16

Updated : 2026-03-09 14:16


NVD link : CVE-2026-3422

Mitre link : CVE-2026-3422

CVE.ORG link : CVE-2026-3422


JSON object : View

Products Affected

edetw

  • u-office_force
CWE
CWE-502

Deserialization of Untrusted Data