External risk intelligence

Univer UniscriptExecutionService Remote Code Execution Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-88404

The vulnerability resides in a script execution service endpoint (/services/script-execution.service.ts). Such services are commonly deployed as web-facing APIs or backend interfaces intended to process external requests, making them typically accessible through internet-facing application surfaces.

Code Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in a script execution service that could allow unauthorized code execution if exploited, impacting the integrity and availability of affected systems. The main concern at this time is confirming the relevance and exposure of this specific service within our environment.

  • Allows arbitrary code execution remotely.
  • Matters if our script services are exposed.
  • Confirm if this specific script service is used.

Attack Path

How an attacker could exploit the issue

An attacker could reach this vulnerability by sending a specially crafted request to the script execution service, which is exposed externally. The vulnerable function within this service can then be triggered by this malicious payload, leading to the execution of arbitrary code. This could allow an attacker to take control of the affected system.

  • No authentication or privileges required.
  • Triggered by a crafted payload.
  • Allows arbitrary code execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated remote attacker to execute arbitrary code by sending a specially crafted payload to the UniscriptExecutionService.execute() function. This could impact the availability and integrity of the affected system.

  • Arbitrary code execution.
  • Attacker sends crafted payload.
  • System compromise.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Univer script execution service is likely managed by an application or platform team, with oversight from security and network teams. Initial triage should focus on identifying all instances of Univer, confirming their exposure and business criticality, and then locating the accountable owner to plan remediation based on risk.

  • Application or platform teams own the issue.
  • Verify Univer instances and their exposure.
  • Plan risk-based remediation activities.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Univer and the UniscriptExecutionService?

Univer is a software framework that includes specialized services for processing automated tasks. The UniscriptExecutionService is a component within this framework designed to handle and run scripts. It acts as an interface that takes input to perform computational operations, serving as the backend engine for applications that require dynamic script execution capabilities.

What does CVE-2026-88404 mean in plain English?

This vulnerability is classified as CWE-94, which refers to Improper Control of Generation of Code. Essentially, the software fails to properly filter instructions provided to it. Because the service incorrectly processes these inputs, an attacker can supply their own malicious commands, which the system then mistakenly executes as if they were legitimate program instructions.

How is the UniscriptExecutionService triggered?

The vulnerability is triggered when the service receives a specially crafted payload sent to its execution function. It is important to note that the system does not require any user interaction or pre-existing credentials to process this request. Simply sending the malicious data to the reachable service endpoint is sufficient to initiate the unintended code execution.

Is my instance of Univer at risk according to Halo Surface Signal?

Halo Surface Signal indicates this vulnerability is highly relevant because the affected service is often deployed as a web-facing API. Because the component is designed to process external requests, it is frequently accessible through internet-facing application surfaces. If your instance is reachable from the public internet, it carries a higher risk of being targeted.

What should I do if I am running Univer?

Your first step is to locate all active instances of the Univer software within your environment to determine which teams are responsible for their operation. Once identified, confirm whether the specific UniscriptExecutionService component is enabled and accessible. Work with your application or platform owners to assess the business impact and prioritize a remediation plan.

References