Junglewise Threat Intelligence

CVE-2026-35440: Microsoft Office Word information disclosure via unauthorized file access

CVE-2026-35440 · Severity: medium · CVSS 5.5 · Published 2026-05-12

Technologies: Microsoft Word, Microsoft Office Word. Vendors: Microsoft.

Executive brief

Microsoft Office Word, a widely used word processing application, contains a vulnerability that could allow unauthorized access to local files. An attacker could exploit this flaw to view sensitive information stored on a user's computer. To succeed, the attacker would typically need to convince a user to open a specially crafted file or perform a specific action within the application.

Technical details

This vulnerability is classified as CWE-552 (Files or Directories Accessible to External Parties) within Microsoft Office Word. The flaw allows an unauthorized attacker to disclose information locally by accessing files or directories that should be restricted. The attack vector is local, requiring user interaction (UI:R), meaning an attacker must likely trick a user into opening a malicious document. Successful exploitation results in high confidentiality impact (C:H) but does not affect system integrity or availability. Microsoft has released an advisory and updates to address this issue.

Affected products

  • Microsoft Office Word

Timeline

  • 2026-05-12: advisory: Initial disclosure by Microsoft and NVD.

References

Related threats