Command Injection in Microsoft products - CVE-2026-68792
Published: August 13, 2026
Vulnerability identifier: #VU142258
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-68792
CWE-ID: CWE-77
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to execute arbitrary commands on the system.
The vulnerability exists due to insufficient input validation in Microsoft Office. A local user can pass specially crafted data to the application and execute arbitrary commands.
Affected software
Microsoft 365 Apps for Enterprise
Microsoft Office
Microsoft Office LTSC
Microsoft Office
Microsoft Office LTSC
How to mitigate CVE-2026-68792
Install updates from vendor's website.