CVE-2026-107781

CVE-2026-107781 published: Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains a server-side request forgery and missing authorization vulnerability in the OnlyOffice save callback editUploadOfficeFileById. Unauthenticated attackers can supply arbitrary ur...

View full NVD advisory → ← Back to CVE watch