CVE-2026-45484
massInsecure Deserialization Privilege Escalation in Microsoft SharePoint Server
CVE-2026-45484 is a deserialization of untrusted data flaw (CWE-502) in Microsoft SharePoint Server that allows an authorized, low-privileged user to elevate privileges. An attacker triggers it by sending crafted serialized data to a vulnerable SharePoint Server over the network; no user interaction is required beyond valid low-privilege access. Successful exploitation yields high impact on confidentiality, integrity, and availability, consistent with compromise of the SharePoint server context and lateral movement from it. Organizations running on-premises SharePoint Server are affected; the specific vulnerable version ranges are not provided in the available data, so defenders should consult Microsoft's advisory (MSRC) for the definitive list. Exploitation has not been confirmed in the wild and no public proof-of-concept is known, but EPSS of 35.2% (98th percentile) indicates a substantial probability of exploitation within 30 days, so patching urgency is high.
What to do: Apply the security update for SharePoint Server referenced in Microsoft's advisory for CVE-2026-45484 as soon as it is available, prioritizing internet-facing farms. Until patched, limit low-privilege authenticated access where possible and monitor for anomalous authenticated requests followed by privilege changes or new admin activity on SharePoint servers. Because no version ranges are provided here, verify your installed SharePoint Server builds against the Microsoft advisory before remediation.
| Microsoft SharePoint Server (on-premises) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
- Vendors
- microsoft
- Products
- sharepoint server
- Weakness
- CWE-502
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.