HIGH

CVE-2026-21509

Microsoft 365 Apps 2026-01-26 CVSS v3.1
CVSS
7.8
KEV

Description

Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.

Summary dbcve.org

This vulnerability in Microsoft Office allows an attacker to bypass a security feature locally by exploiting untrusted inputs in a security decision. The flaw enables an unauthorized user to circumvent security controls through improper validation of input data used in access control or security policy enforcement.

Mitigation

Apply Microsoft security updates for Office when available; verify security feature configurations are working as intended and not being bypassed through unvalidated input paths.

Weakness (CWE)

CWE-807

EPSS Score

72.55%
Probability of exploitation in next 30 days
99.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE