CVE-2026-100206: Medium severity Microsoft 365 Apps for Enterprise vulnerability
Insertion of sensitive information into log file in Microsoft Office allows an authorized attacker to disclose information over a network.
Other sources
Microsoft Office Information Disclosure Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in https://aka.ms/OfficeSecurityReleases
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The attacker must be authorized and have low-level privileges. Exploitation can occur over a network and does not require user interaction.
What is the likely security impact?
Successful exploitation may disclose sensitive information written to a log file. The provided metrics indicate high confidentiality impact, with no stated integrity or availability impact.
Which Office products are listed as affected?
The affected products listed are Microsoft 365 Apps for Enterprise and Microsoft Office LTSC 2021 and LTSC 2024, in both 32-bit and 64-bit editions where specified.