CVE-2026-69273
largeImproper Access Control Allows Authorized-User RCE in Microsoft SharePoint Server
Microsoft has disclosed an improper access control flaw (CWE-284) in SharePoint Server that permits code execution over a network. An authorized attacker — someone holding valid low-privileged credentials — can trigger the flaw remotely with no user interaction or special conditions (AV:N/AC:L), breaking the intended access-control boundaries to run code on the server. Successful exploitation carries high impact on confidentiality, integrity, and availability, effectively giving the attacker code execution on the SharePoint deployment. The affected product per the published data is SharePoint Server, Microsoft's on-premises product, so primarily self-hosted and data-center deployments are in scope. There is no known public proof-of-concept, no CISA KEV listing, and no confirmed in-the-wild exploitation yet; EPSS estimates a 0.5% probability of exploitation within 30 days.
What to do: Since no fixed versions are given in this data, check Microsoft's security update guidance for CVE-2026-69273 and apply the SharePoint Server patch for your installed version as soon as it is available. Until patched, reduce internet exposure of SharePoint front ends and enforce multi-factor authentication plus least privilege on accounts that can reach the server, because exploitation requires valid low-privileged credentials. Monitor for public PoC releases or a CISA KEV listing, which would raise remediation urgency.
| Microsoft SharePoint Server (on-premises) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- Vendors
- microsoft
- Products
- sharepoint server
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.