CVE-2026-41102

Published May 12, 2026

Last updated 3 months ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-41102 is an improper access control vulnerability found in Microsoft Office PowerPoint. This flaw allows an authorized attacker to perform local spoofing. The vulnerability is part of a broader set of issues, collectively referred to as "FlagLeft," affecting several Microsoft 365 Android applications. It stems from a debug flag inadvertently left enabled in a shared Microsoft SDK, which could allow a malicious application on the same device to steal long-lived authentication tokens.

Description
Improper access control in Microsoft Office PowerPoint allows an authorized attacker to perform spoofing locally.
Source
secure@microsoft.com
NVD status
Analyzed
Products
powerpoint

Risk scores

CVSS 3.1

Type
Primary
Base score
5.5
Impact score
3.6
Exploitability score
1.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Severity
MEDIUM

Weaknesses

secure@microsoft.com
CWE-284

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.