CVE-2026-69268
massImproper Access Control Leading to Remote Code Execution in Microsoft SharePoint Server
CVE-2026-69268 is an improper access control flaw (CWE-284) in Microsoft's on-premises SharePoint Server that allows an authorized attacker to execute code over the network. It is triggered remotely by an attacker who already holds valid low-privileged credentials on the deployment (AV:N/AC:L/PR:L with no user interaction required). Successful exploitation yields remote code execution with high confidentiality, integrity, and availability impact (CVSS 3.1 score 8.8 High). The CPE data identifies SharePoint Server (on-premises) as affected; SharePoint Online/Microsoft 365 is not listed, and the exact affected version ranges are not included in the available data, so Microsoft's advisory should be consulted. There is currently no public proof-of-concept, the issue is not in CISA's KEV, and EPSS assigns a 0.7% probability of exploitation within 30 days, so no in-the-wild exploitation is known.
What to do: Apply the SharePoint Server security update referenced for CVE-2026-69268 in Microsoft's advisory as soon as it is published, checking the advisory for the exact affected and fixed versions. Because exploitation requires an authorized account, enforce MFA on accounts with SharePoint access, review recently created or modified accounts for unauthorized access, and restrict network exposure of SharePoint servers (e.g., VPN or firewall rules). With no public PoC or KEV entry yet, keep monitoring Microsoft's guidance and EPSS/KEV status, noting that SharePoint RCE-class flaws have historically been weaponized quickly.
| Microsoft SharePoint Server (Microsoft Office SharePoint, on-premises) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- Vendors
- microsoft
- Products
- sharepoint server
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.