PT-2026-20595 · Xlnt · Xlnt

Oneafter

·

Published

2026-02-19

·

Updated

2026-03-10

·

CVE-2026-2703

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions xlnt versions up to 1.6.1
Description A flaw exists in the xlnt::detail::decode base64 function within the Encrypted XLSX File Parser component, specifically in the source/detail/cryptography/base64.cpp file. This can lead to an off-by-one error. Local access is required for exploitation. The exploit is publicly available.
Recommendations Apply the patch f2d7bf494e5c52706843cf7eb9892821bffb0734 to resolve this issue.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-2703

Affected Products

Xlnt