CVE-2026-3422
Received
Received - Intake
Insecure Deserialization in U-Office Force Enables Remote Code Execution
Publication date: 2026-03-02
Last updated on: 2026-03-09
Assigner: TWCERT/CC
Description
Description
U-Office Force developed by e-Excellence has a Insecure Deserialization vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the server by sending maliciously crafted serialized content.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| edetw | u-office_force | to 29.50 (exc) |
| edetw | u-office_force | 29.50 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-502 | The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid. |