CVE-2026-20945
massAuthenticated cross-site scripting (spoofing) in Microsoft SharePoint Server
CVE-2026-20945 is a cross-site scripting vulnerability (CWE-79) in on-premises Microsoft SharePoint Server caused by improper neutralization of input during web page generation. An attacker holding valid, low-privileged credentials injects malicious script content, and the script executes when another user views the affected page, which means user interaction is required. The attacker gains the ability to run script in the victim's browser within the trusted SharePoint origin, enabling spoofing of page content with limited confidentiality and integrity impact (CVSS 5.4) and no availability impact. Any organization running SharePoint Server on-premises is potentially affected, including deployments exposed to partners or external users, because the attacker only needs an authorized account. No public proof-of-concept or confirmed in-the-wild exploitation is known and it is not in CISA KEV, but EPSS places it in the 98th percentile (25% probability of exploitation within 30 days), so patching should be prioritized.
What to do: Apply the SharePoint Server security update for CVE-2026-20945 referenced in Microsoft's advisory; the data available here does not specify affected builds or KB numbers, so verify exact versions against that advisory. In the interim, review which authenticated users (especially external guests) hold contribute/write permissions on internet-facing SharePoint sites, audit recently modified pages and list items for injected scripts, and treat exposed SharePoint servers as priority patch targets given the elevated EPSS score.
| Microsoft SharePoint Server (on-premises) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- Vendors
- microsoft
- Products
- sharepoint server
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.