Improper access control in Microsoft products - CVE-2026-40420
Published: May 12, 2026
Vulnerability identifier: #VU131287
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-40420
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in Microsoft Office Click-To-Run. A local user can bypass implemented security restrictions and gain elevated privileges on the system.
Affected software
Microsoft 365 Apps for Enterprise
Microsoft Office
Microsoft Office LTSC
Microsoft Office
Microsoft Office LTSC
How to mitigate CVE-2026-40420
Install updates from vendor's website.