CVE-2026-69683
massAuthenticated SSRF in Microsoft SharePoint Server
Microsoft has disclosed CVE-2026-69683, a server-side request forgery (SSRF, CWE-918) flaw in Microsoft Office SharePoint (SharePoint Server). An authenticated attacker with low privileges can trigger it remotely by causing the SharePoint server to issue requests to attacker-chosen or internal network resources; no user interaction is required. Successful exploitation discloses information reachable from the SharePoint server — the CVSS vector shows high confidentiality impact with no integrity or availability impact, and a scope change indicating the forged requests can cross a security boundary. Organizations running SharePoint Server on-premises are affected; the available data does not specify affected versions or editions, and SharePoint Online is not listed among affected products. As of now there is no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns a 0.9% (56th percentile) probability of exploitation within the next 30 days.
What to do: Apply Microsoft's latest security updates for SharePoint Server as published on the Microsoft Security Response Center (MSRC) portal, and confirm affected versions there since the dataset does not list them. Until patched, restrict egress from SharePoint servers to required internal endpoints and review which low-privileged accounts can reach the vulnerable functionality, since low-privilege authentication is sufficient for exploitation. Keep SharePoint servers off direct internet exposure where possible and monitor MSRC guidance for updates to affected versions and exploitation status.
| Microsoft SharePoint Server | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
- Vendors
- microsoft
- Products
- sharepoint server
- Weakness
- CWE-918
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.