HIGH
CVE-2026-21514
CVSS
7.8
KEV
Description
Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally.
Summary dbcve.org
This is a local security feature bypass vulnerability in Microsoft Office Word where the software relies on untrusted inputs when making security decisions. An attacker with local access could potentially bypass a security mechanism by manipulating untrusted input data.
Mitigation
Apply the latest Microsoft Office Word security updates to address this vulnerability, and ensure security features that were bypassed are re-validated after patching.
Weakness (CWE)
CWE-807
EPSS Score
1.54%
Probability of exploitation in next 30 days
73.8th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.