#VU121289 Improper access control in Microsoft Office LTSC and Microsoft 365 Apps for Enterprise - CVE-2026-20949
Published: January 13, 2026
Microsoft Office LTSC
Microsoft 365 Apps for Enterprise
Microsoft
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in Microsoft Excel. A remote attacker can trick a victim to open the malicious workbook, enable editing and then click the attacker‑supplied Quick Access Toolbar (QAT) button to bypass a security feature.