CVE-2026-20943 is an untrusted search path vulnerability in Microsoft Office, Microsoft Office Deployment Tool, and Microsoft SharePoint Server that allows an unauthorized attacker to execute code locally. With a CVSS score of 7.0 (HIGH), successful exploitation requires high attack complexity and user interaction, but can lead to complete compromise of confidentiality, integrity, and availability. Despite its severity, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in CISA's KEV catalog. While community discussion and media coverage are notable, the vulnerability is currently considered inactive on hot lists.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2016:*:*:*:*:*:x64:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2016:*:*:*:*:*:x86:* | ||
< 16.0.19426.20170CPE matchmatch criteria | cpe:2.3:a:microsoft:office_deployment_tool:*:*:*:*:*:*:*:* | ||
< 16.0.19127.20442CPE matchmatch criteria | cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:sharepoint_server:2016:*:*:*:enterprise:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.0 Bluesky, 0.1 Mastodon, and 0.0 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.