Description
Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
Published: 2026-08-20
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper input validation in Microsoft Word enables an unauthorized attacker to disclose information across the network, allowing the reading of confidential data that should remain hidden. The flaw represents a classic confidentiality breach classified under CWE‑20, an information‑disclosure weakness.

Affected Systems

Affected Microsoft Office products include Office 2016, 2019, 2021, 2024 LTSC releases, the 365 Apps for Enterprise suite, and Office 365 for Mac with its 2021 and 2024 Mac LTSC versions. The vulnerability spans both Windows and macOS Word clients; no specific sub‑versions are listed, so all installations within these product families could be impacted.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate risk level. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, implying no confirmed widespread exploitation yet. Because no official hotfix or workaround is provided, the exposure depends on how the attacker interacts with the application—most likely through network‑based document handling or remote exploitation of the validation flaw. The lack of precise exploitation details means the likelihood is uncertain, but the potential confidentiality impact remains significant.

Generated by OpenCVE AI on August 21, 2026 at 00:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft Office security update for Word when it becomes available.
  • If a patch is not yet released, isolate the affected Word installation from untrusted network traffic to limit exposure.
  • Enforce least‑privilege execution for Word and enable file‑access controls to prevent unauthorized read operations.

Generated by OpenCVE AI on August 21, 2026 at 00:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 04 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft microsoft 365
Microsoft office
Microsoft word
CPEs cpe:2.3:a:microsoft:microsoft_365:-:*:*:*:*:macos:*:*
cpe:2.3:a:microsoft:office:2019:-:*:*:*:*:x64:*
cpe:2.3:a:microsoft:office:2019:-:*:*:*:*:x86:*
cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:-:x64:*
cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:-:x86:*
cpe:2.3:a:microsoft:office_2021:-:*:*:*:ltsc:macos:-:*
cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:-:x64:*
cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:-:x86:*
cpe:2.3:a:microsoft:office_2024:-:*:*:*:ltsc:macos:-:*
cpe:2.3:a:microsoft:word:2016:*:*:*:*:*:x64:*
cpe:2.3:a:microsoft:word:2016:*:*:*:*:*:x86:*
Vendors & Products Microsoft microsoft 365
Microsoft office
Microsoft word

Fri, 21 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft microsoft 365 Apps For Enterprise
Microsoft microsoft Office Ltsc For Mac 2021
Microsoft microsoft Office Ltsc For Mac 2024
Microsoft office For Mac
Vendors & Products Microsoft microsoft 365 Apps For Enterprise
Microsoft microsoft Office Ltsc For Mac 2021
Microsoft microsoft Office Ltsc For Mac 2024
Microsoft office For Mac

Fri, 21 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Description Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
Title Microsoft Word Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft 365 Apps
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
Microsoft office 365
Microsoft office Macos 2021
Microsoft office Macos 2024
Microsoft word 2016
Weaknesses CWE-20
CPEs cpe:2.3:a:microsoft:365_apps:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:office_2019:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:office_2021:*:*:*:*:long_term_servicing_channel:*:*:*
cpe:2.3:a:microsoft:office_2024:*:*:*:*:long_term_servicing_channel:*:*:*
cpe:2.3:a:microsoft:office_365:*:*:*:*:*:macos:*:*
cpe:2.3:a:microsoft:office_macos_2021:*:*:*:*:*:long_term_servicing_channel:*:*
cpe:2.3:a:microsoft:office_macos_2024:*:*:*:*:*:long_term_servicing_channel:*:*
cpe:2.3:a:microsoft:word_2016:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft 365 Apps
Microsoft office 2019
Microsoft office 2021
Microsoft office 2024
Microsoft office 365
Microsoft office Macos 2021
Microsoft office Macos 2024
Microsoft word 2016
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft 365 Apps Microsoft 365 Microsoft 365 Apps For Enterprise Microsoft Office Ltsc For Mac 2021 Microsoft Office Ltsc For Mac 2024 Office Office 2019 Office 2021 Office 2024 Office 365 Office For Mac Office Macos 2021 Office Macos 2024 Word Word 2016
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-09T19:38:22.120Z

Reserved: 2026-08-03T23:28:38.301Z

Link: CVE-2026-70105

cve-icon Vulnrichment

Updated: 2026-08-21T11:17:32.839Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-20T22:18:01.723

Modified: 2026-09-04T18:54:07.823

Link: CVE-2026-70105

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T13:00:36Z

Weaknesses
  • CWE-20

    Improper Input Validation