CVE-2026-69417
massAuthenticated Cross-Site Scripting (Spoofing) in Microsoft Office SharePoint
CVE-2026-69417 is a cross-site scripting vulnerability (CWE-79) in Microsoft Office SharePoint caused by improper neutralization of user-supplied input during web page generation. An attacker who already holds low-privilege (authorized) access to the SharePoint environment can inject crafted content, and the flaw is triggered when a victim user interacts with the affected page, executing the attacker's script in the victim's browser session. The described attacker outcome is spoofing, and the CVSS scoring (C:H/I:H) indicates the injected script can compromise the confidentiality and integrity of victim data, potentially letting the attacker act on behalf of the victim in the site's context. Any organization running the affected Microsoft Office SharePoint releases is exposed, since only network access and valid low-privilege credentials are required, plus victim interaction with attacker-influenced content. Exploitation has not been publicly documented: there is no known proof-of-concept, the flaw is not in CISA KEV, and EPSS assigns a modest ~0.7% probability of exploitation within 30 days.
What to do: Apply Microsoft's security update for CVE-2026-69417 as soon as it is released, checking the Microsoft Security Update Guide for the specific affected versions and update identifiers since none were provided in this data. Until patched, restrict contributor/authoring rights on SharePoint sites to trusted users, review recently added or edited content for injected scripts, and prioritize internet-facing SharePoint servers for patching. Because exploitation requires user interaction and none has been observed in the wild yet, this can be handled in the regular monthly patching cycle unless the server is externally exposed.
| Microsoft Office SharePoint | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- Vendors
- microsoft
- Products
- sharepoint server
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.