Junglewise Threat Intelligence

CVE-2026-81394: Microsoft Office Excel information disclosure

CVE-2026-81394 · Severity: medium · CVSS 5.5 · Published 2026-09-08

Executive brief

Microsoft Office Excel contains a vulnerability that exposes sensitive system information to unauthorized access through local attacks. An attacker with local system access could exploit this flaw to read sensitive data stored in or accessible to the Excel application, compromising confidentiality of user and system information.

Technical details

This vulnerability involves exposure of sensitive system information to an unauthorized control sphere in Microsoft Office Excel. The flaw allows local attackers to disclose information without requiring elevated privileges or special preconditions. The attack vector is local, meaning the attacker must have access to the affected system. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Office Excel

Timeline

  • 2026-09-08: disclosed

References

Related threats