CVE-2026-55026
Analyzed Analyzed - Analysis Complete

Integer Overflow in Microsoft Office Leads to Local Information Disclosure

Vulnerability report for CVE-2026-55026, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-14

Last updated on: 2026-07-16

Assigner: Microsoft Corporation

Description

Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-14
Last Modified
2026-07-16
Generated
2026-08-04
AI Q&A
2026-07-14
EPSS Evaluated
2026-08-02
NVD
EUVD

Affected Vendors & Products

Showing 16 associated CPEs
Vendor Product Version / Range
microsoft sharepoint_server 2019
microsoft sharepoint_server 2016
microsoft 365_apps *
microsoft 365_apps *
microsoft office_2019 *
microsoft office_2019 *
microsoft office_2016 *
microsoft office_2016 *
microsoft microsoft_365 *
microsoft office_2021 *
microsoft office_2021 *
microsoft office_2021 *
microsoft office_2024 *
microsoft office_2024 *
microsoft office_2024 *
microsoft sharepoint_server to 16.0.19725.20434 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-190 The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-55026 is an integer overflow or wraparound vulnerability in Microsoft Office. This flaw allows an unauthorized attacker to disclose information locally on the affected system.

An integer overflow occurs when a calculation exceeds the maximum limit of an integer data type, causing it to wrap around to a smaller value. In this case, the vulnerability could be exploited to access sensitive information that the attacker would not normally have permission to view.

Detection Guidance

The provided context does not include specific detection methods or commands for identifying the integer overflow or wraparound vulnerability in Microsoft Office (CVE-2026-55026) on a network or system. Detection typically involves checking for vulnerable versions of Microsoft Office or using security tools that can identify such vulnerabilities.

For accurate detection, refer to Microsoft's official guidance or security tools that scan for vulnerable software versions. You may also monitor for unusual local information disclosure attempts, though this is not a direct detection method.

Impact Analysis

This vulnerability can impact you in the following ways:

  • An attacker with local access to your system could exploit this flaw to disclose sensitive information stored or processed by Microsoft Office.
  • The disclosed information could include confidential documents, credentials, or other sensitive data, potentially leading to further attacks or unauthorized access.

Since the CVSS vector indicates a high confidentiality impact (C:H), the risk of information exposure is significant if the vulnerability is exploited.

Compliance Impact

This vulnerability could affect compliance with common standards and regulations in the following ways:

  • GDPR: If the disclosed information includes personal data of EU citizens, this could constitute a data breach under GDPR. Organizations may be required to report the breach and could face fines if they failed to implement adequate security measures.
  • HIPAA: If the affected system processes protected health information (PHI), the information disclosure could violate HIPAA's Privacy Rule. Covered entities may need to report the breach and could face penalties for non-compliance.

Compliance with these regulations often requires organizations to maintain the confidentiality of sensitive data. Exploitation of this vulnerability could lead to violations if the disclosed information is protected under such regulations.

Mitigation Strategies

To mitigate CVE-2026-55026, follow these immediate steps:

  • Apply the latest security updates provided by Microsoft for Microsoft Office. Refer to the Microsoft Update Guide for the specific patch related to this CVE.
  • Ensure that all Microsoft Office installations are updated to the latest version, as older versions may be vulnerable.
  • Restrict local access to systems running vulnerable versions of Microsoft Office until patches are applied.
  • Monitor Microsoft's official communications for additional mitigation advice or workarounds if patches are not immediately available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-55026. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart