CVE-2026-88405

9.8

Univer · Univer

A remote code execution vulnerability exists in the RemoteRegisterFunctionService function of Univer v1.0.0-alpha.2, allowing unauthenticated attackers to execute arbitrary code via a crafted payload.

Executive summary

Univer v1.0.0-alpha.2 contains a critical remote code execution vulnerability that allows unauthenticated attackers to gain full control over the affected system.

Vulnerability

The vulnerability exists in the RemoteRegisterFunctionService function located at /remote/remote-register-function.service.ts. It is an unauthenticated remote code execution flaw that permits an attacker to send a specially crafted payload to trigger arbitrary command execution.

Business impact

The potential impact of this vulnerability is total system compromise, as it allows for unauthorized code execution with the privileges of the application. Given the CVSS score of 9.8, this represents a critical risk that could lead to full data exfiltration, service disruption, and complete loss of system integrity.

Remediation

Immediate Action: Since no official patch is currently available, users should restrict network access to the affected service and disable the vulnerable functionality if possible.

Proactive Monitoring: Security teams should monitor ingress traffic for suspicious payloads directed at the /remote/remote-register-function.service.ts endpoint and review application logs for unauthorized execution attempts.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules designed to inspect and block malicious payloads targeting remote service registration functions.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

The severity of this vulnerability necessitates immediate attention, as it provides a clear path for unauthenticated attackers to achieve full system compromise. Organizations running Univer v1.0.0-alpha.2 must prioritize isolating the affected component until a vendor-supplied update is released and verified.

More Univer CVEs

History

CVE Brief tracked this CVE 3 days before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 9.8 (3.1) from cvelistV5
  4. Analyst report written
  5. Published in the daily brief critical section, early-warning entry

Sources