ZeroHour

CVE-2026-69273

large

Improper Access Control Allows Authorized-User RCE in Microsoft SharePoint Server

CVSS 3.1
8.8 high
EPSS
<1%p43
Published
()
Modified
AI analysis

Microsoft has disclosed an improper access control flaw (CWE-284) in SharePoint Server that permits code execution over a network. An authorized attacker — someone holding valid low-privileged credentials — can trigger the flaw remotely with no user interaction or special conditions (AV:N/AC:L), breaking the intended access-control boundaries to run code on the server. Successful exploitation carries high impact on confidentiality, integrity, and availability, effectively giving the attacker code execution on the SharePoint deployment. The affected product per the published data is SharePoint Server, Microsoft's on-premises product, so primarily self-hosted and data-center deployments are in scope. There is no known public proof-of-concept, no CISA KEV listing, and no confirmed in-the-wild exploitation yet; EPSS estimates a 0.5% probability of exploitation within 30 days.

What to do: Since no fixed versions are given in this data, check Microsoft's security update guidance for CVE-2026-69273 and apply the SharePoint Server patch for your installed version as soon as it is available. Until patched, reduce internet exposure of SharePoint front ends and enforce multi-factor authentication plus least privilege on accounts that can reach the server, because exploitation requires valid low-privileged credentials. Monitor for public PoC releases or a CISA KEV listing, which would raise remediation urgency.

Affected
Microsoft SharePoint Server (on-premises)
Estimated exposure
largetens of thousands of internet-exposed SharePoint Server instances (roughly 30k-50k hosts in public scans), with more total on-prem deployments — Public internet scans (Shodan/Censys) typically show on the order of tens of thousands of SharePoint Server instances reachable online, while many additional on-prem deployments sit behind firewalls and Microsoft publishes no install…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Vendors
microsoft
Products
sharepoint server
Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.