
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20949 is an improper access control vulnerability in Microsoft Office Excel that allows an unauthorized local attacker to bypass a security feature. It was disclosed and patched on January 13, 2026, as part of Microsoft's January 2026 Patch Tuesday security update release. Affected products include Microsoft Office LTSC 2021 and 2024 (Windows and macOS), Microsoft 365 Apps for Enterprise, Office 2021, and Office 2024. The vulnerability carries a CVSS v3.1 base score of 7.8 (High), assigned by Microsoft (Microsoft MSRC, Feedly).
The vulnerability is classified under CWE-284 (Improper Access Control), meaning Excel fails to properly enforce access restrictions that would normally prevent unauthorized actions (Microsoft MSRC). The attack vector is local, requiring no elevated privileges but necessitating user interaction — typically opening a maliciously crafted Excel file. This allows an attacker to bypass built-in Excel security controls, potentially circumventing protections such as Protected View, macro restrictions, or other file-based security features. No public proof-of-concept or detailed technical write-up has been published as of the time of this report (Feedly).
Successful exploitation results in high impact to confidentiality, integrity, and availability of the affected system, as reflected in the CVSS scoring. An attacker who tricks a user into opening a crafted Excel document could bypass security features designed to protect against malicious content, potentially enabling unauthorized access to spreadsheet data, modification of content, or disruption of application functionality. The scope is limited to the local system and does not inherently enable network-level lateral movement, but could serve as an initial foothold in a broader attack chain (Feedly).
.xlsx or .xlsm file designed to trigger the improper access control condition in Excel, potentially embedding content that would normally be blocked by Excel's security features (e.g., macros, external links, or embedded objects)..xlsx, .xlsm, .xlsb) in user download directories, temp folders (%TEMP%, %APPDATA%), or email attachment staging areas; presence of files with mismatched extensions.EXCEL.EXE (e.g., cmd.exe, powershell.exe, wscript.exe, mshta.exe) shortly after a file is opened.EXCEL.EXE to external IP addresses or domains, particularly following the opening of an Excel file from an untrusted source.Microsoft released security updates on January 13, 2026, addressing this vulnerability across all affected products. Users should apply the January 2026 Patch Tuesday updates for Microsoft Office LTSC 2021, LTSC 2024, Office 2021, Office 2024 (including Mac versions), and Microsoft 365 Apps for Enterprise; updates are available via https://aka.ms/OfficeSecurityReleases (Microsoft MSRC). For macOS, the fixed version is 16.105.26011018 or later. As a workaround prior to patching, organizations should train users to avoid opening Excel files from untrusted sources and consider enforcing macro-blocking Group Policy settings. Enabling Microsoft Defender for Office 365 and ensuring Protected View is active can also reduce exposure.
CVE-2026-20949 was covered as part of broader January 2026 Patch Tuesday roundups by security outlets including BleepingComputer, Sophos, Zero Day Initiative (ZDI), Computerworld, and SANS ISC, though it did not receive individual spotlight coverage given the absence of active exploitation (BleepingComputer, ZDI, Sophos). Community discussion on platforms like Windows Forum noted the security feature bypass nature of the flaw and emphasized patch readiness. No significant independent researcher commentary or threat actor attribution has been publicly reported.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."