Junglewise Threat Intelligence

CVE-2026-40421: Microsoft Office Word information disclosure via path traversal

CVE-2026-40421 · Severity: medium · CVSS 4.3 · Published 2026-05-12

Technologies: Microsoft Word, Microsoft Office Word. Vendors: Microsoft.

Executive brief

A vulnerability in Microsoft Word could allow an unauthorized person to access sensitive information over a network. This occurs when the application incorrectly handles file paths or names provided by an external source. An attacker could potentially use this to view files or data they are not authorized to see, though it requires some level of user interaction.

Technical details

This vulnerability is classified as CWE-73 (External Control of File Name or Path) within Microsoft Office Word. It allows a remote, unauthenticated attacker to disclose sensitive information by manipulating file paths or names that the application processes. The attack vector is network-based and requires low architectural complexity, but it does necessitate user interaction (UI:R) to be successful. Exploitation results in a partial loss of confidentiality (C:L) without impacting system integrity or availability.

Affected products

  • Microsoft Office Word

Timeline

  • 2026-05-12: disclosed: Initial disclosure by Microsoft
  • 2026-05-12: advisory: NVD record published

References

Related threats