Improper access control in Microsoft products - CVE-2026-45649
Published: June 12, 2026
Vulnerability identifier: #VU134479
CSH Severity: High
CVSS v4: 8.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-45649
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in Office for Android. A remote attacker can trick a victim to open a specially crafted Office file and perform spoofing attack on the system.
Affected software
Microsoft Word for Android
Microsoft PowerPoint for Android
Microsoft Excel for Android
Microsoft PowerPoint for Android
Microsoft Excel for Android
How to mitigate CVE-2026-45649
Install updates from vendor's website.