CRITICAL🇵🇱 Wersja polska

CVE-2026-3422

CVSS 9.3v4.0pub. 2026-03-02upd. 2026-03-09

U-Office Force developed by e-Excellence has a Insecure Deserialization vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the server by sending maliciously crafted serialized content.

🤖 AI Analysis
How it works

Attacker sends specially crafted malicious serialized data to the vulnerable endpoint of the U-Office Force application. The server deserializes the received data without proper validation of its content, leading to execution of malicious code embedded in it. The attack can be carried out remotely over the network without requiring any access credentials.

Impact

Attacker gains the ability to execute arbitrary code on the server (RCE), which in practice may mean complete system takeover, data theft, malicious software installation, or further lateral movement in the organization's network.

Mitigation & patch

Apply patches available from the vendor according to references. Detailed information about patched versions is available at: https://www.twcert.org.tw/en/cp-139-10743-9a952-2.html and https://www.twcert.org.tw/tw/cp-132-10742-45b13-1.html

Who is affected

Edetw U-Office Force — versions indicated in vendor references (TWCERT)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Edetw U Office Force

    APP
    Edetw
    29.50< 29.50
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEDeserialization
CWE
References

Related vulnerabilities

CVE-2025-2395CRITICAL9.8PL ✓same product

U-Office Force: Nieautoryzowane logowanie jako administrator przez manipulację cookies

CVE-2023-32757CRITICAL9.8PL ✓same product

e-Excellence U-Office Force — niekontrolowany upload pliku umożliwiający RCE

CVE-2025-12864HIGH8.7same product

U-Office Force developed by e-Excellence has a SQL Injection vulnerability, allowing authenticated remote atta...

CVE-2025-12865HIGH8.7same product

U-Office Force developed by e-Excellence has a SQL Injection vulnerability, allowing authenticated remote atta...

CVE-2025-2396HIGH8.8same product

The U-Office Force from e-Excellence has an Arbitrary File Upload vulnerability, allowing remote attackers wit...