CVE-2026-69716
largeSQL Injection Privilege Escalation in Microsoft SharePoint Server
CVE-2026-69716 is a SQL injection flaw (CWE-89) in Microsoft Office SharePoint in which special elements are not properly neutralized before being used in an SQL command. A remote attacker who already holds authorized (low-privilege) credentials sends crafted input over the network that reaches the database layer, allowing the injection to execute. Successful exploitation elevates the attacker's privileges on the affected SharePoint Server deployment, with the CVSS vector indicating high impact on confidentiality, integrity, and availability. The affected product per the CVE data is on-premises Microsoft SharePoint Server; organizations running it should treat authenticated users as potential exploit sources. As of this writing there is no known exploitation in the wild, no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates a 0.9% chance of exploitation within 30 days.
What to do: Track Microsoft's advisory and apply the SharePoint Server security update as soon as it is released through Microsoft's regular update channels; do not delay patching on internet-facing farms. Because exploitation requires only an authorized low-privilege account, enforce MFA, review and remove unused SharePoint accounts, and restrict network exposure of SharePoint front-end servers. Monitor for anomalous database queries or unexpected privilege changes in SharePoint logs until patches are fully deployed.
| Microsoft SharePoint Server | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
- Vendors
- microsoft
- Products
- sharepoint server
- Weakness
- CWE-89
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.