CVE-2026-69464
mass1Privilege Escalation via Excess-Privilege Execution in Microsoft SharePoint Server
CVE-2026-69464 is a privilege-escalation flaw (CWE-250, execution with unnecessary privileges) in Microsoft's on-premises SharePoint Server, in which certain server-side operations run with more privileges than they require. An attacker holding any valid low-privileged SharePoint account can trigger the flaw remotely over the network, with no user interaction required. Successful exploitation elevates the attacker's privileges on the affected SharePoint server, with high impact on confidentiality, integrity, and availability per the CVSS 3.1 vector (8.8, High). Organizations running SharePoint Server on-premises are affected; the available data does not specify exact affected version ranges, and the cloud offering (SharePoint Online) is not listed among affected products. There is currently no known exploitation, no public proof-of-concept, and no CISA KEV listing; EPSS estimates a 0.9% probability of exploitation within 30 days (58th percentile).
What to do: Review Microsoft's security advisory to determine whether your SharePoint Server edition/branch is affected and apply the patch Microsoft releases for this flaw, then verify installed build numbers before and after updating. In the interim, restrict which low-privileged accounts can authenticate to and reach the SharePoint server over the network, and monitor for updated guidance since no public PoC or in-the-wild exploitation is currently known.
| Microsoft SharePoint Server (Microsoft Office SharePoint) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
- Vendors
- microsoft
- Products
- sharepoint server
- Weakness
- CWE-250
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.