CVE-2026-69282
largeAuthenticated RCE via Improper Access Control in Microsoft SharePoint Server
CVE-2026-69282 is an improper access control vulnerability (CWE-284) in Microsoft Office SharePoint Server that allows an authorized attacker to execute arbitrary code over the network. It is triggered by an attacker holding valid, low-privileged credentials who sends crafted network requests to a vulnerable SharePoint Server deployment, with no user interaction required. Successful exploitation yields code execution on the SharePoint server with high confidentiality, integrity, and availability impact (CVSS 3.1 score of 8.8), potentially enabling full server compromise and access to stored corporate content. Organizations running on-premises SharePoint Server are the affected population; the advisory data lists only "SharePoint Server," not the cloud-hosted SharePoint Online service. As of this analysis there are no known exploits, no public proof-of-concept, the issue is not in CISA's KEV catalog, and EPSS estimates only a ~0.5% chance of exploitation within 30 days.
What to do: Patch as soon as Microsoft releases the security update, using the MSRC advisory to identify the affected SharePoint Server builds, since specific version numbers are not provided in the available data. Until patched, limit exposure of SharePoint servers to untrusted networks, review which low-privileged accounts can reach the environment (the attacker only needs PR:L access), and monitor for unusual authenticated activity. Because there is no known exploitation or public PoC, prioritization can be moderate, but SharePoint's history as a high-value attack surface warrants prompt remediation.
| Microsoft SharePoint Server | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- Vendors
- microsoft
- Products
- sharepoint server
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.