Vulnerability · NVD
CVE-2026-41101
CVE-2026-41101, high severity (CVSS 7.1): 1 tracked app concerned, all fixed or indeterminable on their current version.
- Severity (CVSS)
- 7.1
- Exploitation
- 0.3 %
- Tracked apps
- 1
- Still exposed
- 0
NVD scale
EPSS, predicted over 30 days
Improper access control in Microsoft Office Word allows an authorized attacker to perform spoofing locally.
Attack vector : Local
No user interaction
Show raw CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
EPSS
0.31%
exploit very unlikely
percentile 21.2%
Tracked apps referencing this CVE
For each app: the affected range, the fixing version, and where the tracked app stands today.
-
Observed affected builds (29)
16.0.19822.20104 16.0.19822.20038 16.0.19725.20058 16.0.19628.20074 16.0.19530.20070 16.0.19328.20086 16.0.19231.20090 16.0.19127.20134 16.0.19029.20110 16.0.18526.20030 16.0.18429.20094 16.0.18324.20086 16.0.17830.20082 16.0.17328.20152 16.0.16501.20160 16.0.15629.20092 16.0.15427.20090 16.0.15128.20206 16.0.14729.20146 16.0.14527.20162 16.0.14326.20140 16.0.14228.20138 16.0.13801.20162 16.0.13127.20162 16.0.13029.20182 16.0.12624.20254 16.0.12130.20208 16.0.11001.20074 16.0.10827.20078
Vulnerable CPE configurations (1)
| Vendor | Product | Platform | Versions | CPE 2.3 URI |
|---|---|---|---|---|
| microsoft |
word Android
|
Android | <16.0.19822.20190 | cpe:2.3:a:microsoft:word:*:*:*:*:*:android:*:* |
Manage your fleet with Appaloosa
Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.