Description
Improper validation of specified type of input in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
Published: 2026-07-14
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Microsoft Office Word contains an improper input validation flaw that allows an unauthorized local user to disclose sensitive information. This vulnerability is mapped to CWE‑20 (Improper Input Validation) and CWE‑1287 (Information Disclosure).

Affected Systems

The flaw affects a broad range of Microsoft Office products, including Microsoft 365 Apps for Enterprise, Office 2019, Office 2021, Office 2024, Office 365 for Mac, Office LTSC 2021 and 2024, Office LTSC for Mac 2021 and 2024, and Word 2016. SharePoint Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition are also affected. Version detail is not specified in the CVE.

Risk and Exploitability

With a CVSS score of 5.5 the vulnerability is considered moderate. The EPSS score of < 1% indicates a very low probability of exploitation. The vulnerability is local only; an attacker must already have local access to a machine and exploit the flaw by submitting a crafted input that triggers the improper validation. As it is not listed in the CISA KEV catalog, there are no known widespread exploits, but the limited exploitability does not eliminate the need for vigilance.

Generated by OpenCVE AI on July 31, 2026 at 06:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply all current Microsoft Office and SharePoint security updates that address CVE-2026-55124.
  • Limit local access to documents and input types that could trigger the flaw by applying file permissions, group restrictions, or containerization.
  • Enforce least authorized users can create or modify Office documents on vulnerable systems.

Generated by OpenCVE AI on July 31, 2026 at 06:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 16 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description Improper validation of specified type of input in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
Title Microsoft Word Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft 365 Apps
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
Microsoft office 365
Microsoft office Macos 2021
Microsoft office Macos 2024
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
Microsoft word 2016
Weaknesses CWE-1287
CWE-20
CPEs cpe:2.3:a:microsoft:365_apps:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:office_2019:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:office_2021:*:*:*:*:long_term_servicing_channel:*:*:*
cpe:2.3:a:microsoft:office_2024:*:*:*:*:long_term_servicing_channel:*:*:*
cpe:2.3:a:microsoft:office_365:*:*:*:*:*:macos:*:*
cpe:2.3:a:microsoft:office_macos_2021:*:*:*:*:*:long_term_servicing_channel:*:*
cpe:2.3:a:microsoft:office_macos_2024:*:*:*:*:*:long_term_servicing_channel:*:*
cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2016:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2019:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:word_2016:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft 365 Apps
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
Microsoft office 365
Microsoft office Macos 2021
Microsoft office Macos 2024
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
Microsoft word 2016
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft 365 Apps Office 2019 Office 2021 Office 2024 Office 365 Office Macos 2021 Office Macos 2024 Sharepoint Server Sharepoint Server 2016 Sharepoint Server 2019 Word 2016
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-03T22:57:07.910Z

Reserved: 2026-06-16T15:03:49.680Z

Link: CVE-2026-55124

cve-icon Vulnrichment

Updated: 2026-07-14T19:07:58.292Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T07:00:08Z

Weaknesses
  • CWE-1287

    Improper Validation of Specified Type of Input

  • CWE-20

    Improper Input Validation