ZeroHour

CVE-2026-69716

large

SQL Injection Privilege Escalation in Microsoft SharePoint Server

CVSS 3.1
8.8 high
EPSS
<1%p58
Published
()
Modified
AI analysis

CVE-2026-69716 is a SQL injection flaw (CWE-89) in Microsoft Office SharePoint in which special elements are not properly neutralized before being used in an SQL command. A remote attacker who already holds authorized (low-privilege) credentials sends crafted input over the network that reaches the database layer, allowing the injection to execute. Successful exploitation elevates the attacker's privileges on the affected SharePoint Server deployment, with the CVSS vector indicating high impact on confidentiality, integrity, and availability. The affected product per the CVE data is on-premises Microsoft SharePoint Server; organizations running it should treat authenticated users as potential exploit sources. As of this writing there is no known exploitation in the wild, no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates a 0.9% chance of exploitation within 30 days.

What to do: Track Microsoft's advisory and apply the SharePoint Server security update as soon as it is released through Microsoft's regular update channels; do not delay patching on internet-facing farms. Because exploitation requires only an authorized low-privilege account, enforce MFA, review and remove unused SharePoint accounts, and restrict network exposure of SharePoint front-end servers. Monitor for anomalous database queries or unexpected privilege changes in SharePoint logs until patches are fully deployed.

Affected
Microsoft SharePoint Server
Estimated exposure
largeon the order of 100,000 internet-exposed SharePoint Server instances, plus a larger intranet-only installed base (exact count unknown) — Public internet scans conducted during prior SharePoint Server vulnerability campaigns have consistently found roughly 10^5 exposed SharePoint instances, and the on-premises installed base is far larger, though many deployments are…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

Vendors
microsoft
Products
sharepoint server
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.