CVE-2026-69402
massCross-site scripting in Microsoft SharePoint enables authenticated spoofing
CVE-2026-69402 is a cross-site scripting vulnerability (CWE-79) in Microsoft Office SharePoint caused by improper neutralization of input during web page generation. It is triggered over a network when an attacker who already holds authorized (low-privilege) access injects crafted content into the site; because user interaction is required, a victim must then view or invoke that content for the script to run in their browser session. Successful execution allows the attacker to perform spoofing, effectively running script in the victim's context to impersonate the site or its users, with high confidentiality and integrity impact but no availability impact. Any organization running an affected SharePoint deployment is exposed to the flaw, but the prerequisite of valid credentials limits would-be attackers to authenticated users rather than anonymous internet traffic. As of this analysis there is no known public proof-of-concept, it is not listed in CISA's KEV, and its EPSS of 0.6% (roughly the 49th percentile) suggests limited exploitation risk in the next 30 days.
What to do: Review Microsoft's advisory for CVE-2026-69402 and apply the security update it specifies for your SharePoint version as soon as it is deployed. Until patched, audit low-privilege site memberships and limit who can create or edit user-facing content, since the flaw requires authenticated access and user interaction. Check outbound web traffic and recent page content changes for signs of injected script, though no in-the-wild exploitation is currently known.
| Microsoft Office SharePoint | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- Vendors
- microsoft
- Products
- sharepoint server
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.