ZeroHour

CVE-2026-69417

mass

Authenticated Cross-Site Scripting (Spoofing) in Microsoft Office SharePoint

CVSS 3.1
5.4 medium
EPSS
<1%p38
Published
()
Modified
AI analysis

CVE-2026-69417 is a cross-site scripting vulnerability (CWE-79) in Microsoft Office SharePoint caused by improper neutralization of user-supplied input during web page generation. An attacker who already holds low-privilege (authorized) access to the SharePoint environment can inject crafted content, and the flaw is triggered when a victim user interacts with the affected page, executing the attacker's script in the victim's browser session. The described attacker outcome is spoofing, and the CVSS scoring (C:H/I:H) indicates the injected script can compromise the confidentiality and integrity of victim data, potentially letting the attacker act on behalf of the victim in the site's context. Any organization running the affected Microsoft Office SharePoint releases is exposed, since only network access and valid low-privilege credentials are required, plus victim interaction with attacker-influenced content. Exploitation has not been publicly documented: there is no known proof-of-concept, the flaw is not in CISA KEV, and EPSS assigns a modest ~0.7% probability of exploitation within 30 days.

What to do: Apply Microsoft's security update for CVE-2026-69417 as soon as it is released, checking the Microsoft Security Update Guide for the specific affected versions and update identifiers since none were provided in this data. Until patched, restrict contributor/authoring rights on SharePoint sites to trusted users, review recently added or edited content for injected scripts, and prioritize internet-facing SharePoint servers for patching. Because exploitation requires user interaction and none has been observed in the wild yet, this can be handled in the regular monthly patching cycle unless the server is externally exposed.

Affected
Microsoft Office SharePoint
Estimated exposure
masshundreds of millions of users; tens of thousands of internet-exposed SharePoint Server instances visible in public scans — SharePoint is among the most widely deployed collaboration platforms, delivered via Microsoft 365 to hundreds of millions of commercial seats and running on-premises in a large share of enterprise environments, with public internet scans…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Vendors
microsoft
Products
sharepoint server
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.