ZeroHour

CVE-2026-20945

mass

Authenticated cross-site scripting (spoofing) in Microsoft SharePoint Server

CVSS 3.1
5.4 medium
EPSS
25%p98
Published
()
Modified
AI analysis

CVE-2026-20945 is a cross-site scripting vulnerability (CWE-79) in on-premises Microsoft SharePoint Server caused by improper neutralization of input during web page generation. An attacker holding valid, low-privileged credentials injects malicious script content, and the script executes when another user views the affected page, which means user interaction is required. The attacker gains the ability to run script in the victim's browser within the trusted SharePoint origin, enabling spoofing of page content with limited confidentiality and integrity impact (CVSS 5.4) and no availability impact. Any organization running SharePoint Server on-premises is potentially affected, including deployments exposed to partners or external users, because the attacker only needs an authorized account. No public proof-of-concept or confirmed in-the-wild exploitation is known and it is not in CISA KEV, but EPSS places it in the 98th percentile (25% probability of exploitation within 30 days), so patching should be prioritized.

What to do: Apply the SharePoint Server security update for CVE-2026-20945 referenced in Microsoft's advisory; the data available here does not specify affected builds or KB numbers, so verify exact versions against that advisory. In the interim, review which authenticated users (especially external guests) hold contribute/write permissions on internet-facing SharePoint sites, audit recently modified pages and list items for injected scripts, and treat exposed SharePoint servers as priority patch targets given the elevated EPSS score.

Affected
Microsoft SharePoint Server (on-premises)
Estimated exposure
mass≈100,000+ SharePoint Server installations worldwide (tens of thousands internet-exposed per public scans, many more deployed internally) — SharePoint Server remains broadly deployed across enterprises, government and education, and prior internet-wide scans (e.g., Shodan/Shadowserver) have repeatedly identified tens of thousands of internet-facing SharePoint instances, with…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Vendors
microsoft
Products
sharepoint server
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.