Improper access control in Microsoft Office LTSC and Microsoft Word for Android - CVE-2026-42832
Published: May 13, 2026
Vulnerability identifier: #VU131320
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-42832
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in Microsoft Office. A local attacker can bypass implemented security restrictions and perform spoofing attack on the system.
Affected software
Microsoft Office LTSC
Microsoft Word for Android
Microsoft Word for Android
How to mitigate CVE-2026-42832
Install updates from vendor's website.
Microsoft Word for Android - update to 16.0.19822.20190