CVE-2026-26134

7.8

Microsoft · Office for Android

A local integer overflow vulnerability in Microsoft Office for Android allows an authenticated attacker to achieve privilege escalation.

Executive summary

A high-severity integer overflow vulnerability in Microsoft Office for Android allows an authenticated attacker to elevate privileges on the local device.

Vulnerability

The vulnerability is an integer overflow or wraparound condition (CWE-190) that, when triggered locally by an authenticated user, can lead to privilege escalation. The attack vector is local, meaning the attacker must already have a presence on the device to exploit the flaw.

Business impact

Successful exploitation allows an attacker to gain elevated privileges on the affected mobile device, potentially bypassing standard OS security controls. Given the CVSS score of 7.8, this represents a significant risk to data confidentiality and integrity, as elevated access could facilitate unauthorized data extraction or further malicious activity within the application environment.

Remediation

Immediate Action: Update Microsoft Office for Android to version 16.0.19822.20000 or later via the official Google Play Store or enterprise management console.

Proactive Monitoring: Monitor device logs for anomalous application behavior or unexpected process crashes that may indicate exploitation attempts.

Compensating Controls: Ensure that mobile device management (MDM) policies restrict unauthorized application installation and enforce regular security updates for all installed software.

Exploitation status

Public Exploit Available: No

Analyst recommendation

This vulnerability presents a clear risk of privilege escalation for Android users. Organizations should prioritize the deployment of the vendor-supplied update across all managed mobile devices to remediate the underlying integer overflow flaw and prevent potential unauthorized access to sensitive application data.

More Microsoft CVEs

Sources