Improper access control in Microsoft 365 Apps for Enterprise and Microsoft Office LTSC - CVE-2026-20949
Published: January 13, 2026
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in Microsoft Excel. A remote attacker can trick a victim to open the malicious workbook, enable editing and then click the attacker‑supplied Quick Access Toolbar (QAT) button to bypass a security feature.
Affected software
Microsoft Office LTSC