CVE-2026-69724
largeMissing Authorization in Microsoft SharePoint Server Enables Authenticated RCE
CVE-2026-69724 is a missing-authorization flaw (CWE-862) in Microsoft Office SharePoint Server that fails to properly verify permissions on a code-execution path. An attacker who already holds valid, low-privileged credentials can send a crafted network request that triggers the vulnerable routine without the expected authorization check. Successful exploitation yields remote code execution in the context of the SharePoint server, with high impact on confidentiality, integrity, and availability. Any organization running an affected on-premises SharePoint Server deployment is exposed, particularly where the server is reachable from untrusted networks. As of now there is no public proof-of-concept, no known in-the-wild exploitation, and the flaw is not in the CISA KEV catalog; EPSS currently estimates a 0.8% probability of exploitation within 30 days.
What to do: Apply the SharePoint Server security update from Microsoft as soon as it is available, and verify the installed build against Microsoft's advisory to confirm full remediation. Because the flaw requires valid credentials, review and tighten SharePoint account privileges, restrict network access to the server (VPN or firewall rules) in the interim, and monitor authentication logs for unexpected low-privileged account activity.
| microsoft SharePoint Server | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- Vendors
- microsoft
- Products
- sharepoint server
- Weakness
- CWE-862
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.