ZeroHour

CVE-2026-69804

large

TOCTOU Race Condition Enables Authenticated Remote Code Execution in Microsoft SharePoint

CVSS 3.1
7.5 high
EPSS
<1%p42
Published
()
Modified
AI analysis

CVE-2026-69804 is a time-of-check to time-of-use (TOCTOU) race condition (CWE-367) in Microsoft Office SharePoint, a timing flaw in which the state of a file or resource can change between the moment SharePoint validates it and the moment it acts on it. An authorized, low-privilege attacker can trigger it over the network by issuing requests timed to win that check-to-use race window; the high attack complexity (AC:H in the CVSS vector) means exploitation is timing-sensitive rather than trivially repeatable. A successful race lets the attacker execute code on the SharePoint server, with high impact to the confidentiality, integrity, and availability of SharePoint-hosted content. Per the vulnerability data, affected products are on-premises SharePoint Server from Microsoft; no cloud product is listed. As of this analysis there is no known in-the-wild exploitation, no public proof-of-concept, and no CISA KEV listing, and EPSS estimates only a ~0.5% probability of exploitation within 30 days.

What to do: Inventory all SharePoint Server deployments and apply Microsoft's security update for CVE-2026-69804 as soon as it is released, prioritizing servers reachable by any authenticated user from an untrusted network. Until patched, restrict network access to SharePoint servers and monitor for publication of a PoC or KEV listing, which would raise the response priority.

Affected
microsoft SharePoint Server
Estimated exposure
largetens of thousands of on-premises SharePoint Server deployments, likely on the order of 10k-100k servers with a subset internet-exposed (estimate) — Internet-wide scans published during prior SharePoint Server RCE waves in 2025 counted tens of thousands of exposed SharePoint instances, indicating a large on-prem install base; this is an estimate, and no per-version exposure data is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Time-of-check time-of-use (toctou) race condition in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Vendors
microsoft
Products
sharepoint server
Weakness
CWE-367
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.