ZeroHour

CVE-2026-69724

large

Missing Authorization in Microsoft SharePoint Server Enables Authenticated RCE

CVSS 3.1
8.8 high
EPSS
<1%p54
Published
()
Modified
AI analysis

CVE-2026-69724 is a missing-authorization flaw (CWE-862) in Microsoft Office SharePoint Server that fails to properly verify permissions on a code-execution path. An attacker who already holds valid, low-privileged credentials can send a crafted network request that triggers the vulnerable routine without the expected authorization check. Successful exploitation yields remote code execution in the context of the SharePoint server, with high impact on confidentiality, integrity, and availability. Any organization running an affected on-premises SharePoint Server deployment is exposed, particularly where the server is reachable from untrusted networks. As of now there is no public proof-of-concept, no known in-the-wild exploitation, and the flaw is not in the CISA KEV catalog; EPSS currently estimates a 0.8% probability of exploitation within 30 days.

What to do: Apply the SharePoint Server security update from Microsoft as soon as it is available, and verify the installed build against Microsoft's advisory to confirm full remediation. Because the flaw requires valid credentials, review and tighten SharePoint account privileges, restrict network access to the server (VPN or firewall rules) in the interim, and monitor authentication logs for unexpected low-privileged account activity.

Affected
microsoft SharePoint Server
Estimated exposure
largetens of thousands of servers, likely on the order of 100,000+ SharePoint Server deployments worldwide (public scans during past SharePoint flaws have shown… — Microsoft does not publish install counts, but SharePoint Server is a widely deployed enterprise on-premises product, and independent internet-wide scans during previous SharePoint vulnerabilities have identified on the order of tens to…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Vendors
microsoft
Products
sharepoint server
Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.