Description
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
Published: 2026-03-10
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑site scripting leading to spoofing
Action: Patch promptly
AI Analysis

Impact

The vulnerability is an improper neutralization of input during web page generation (CWE‑79), commonly known as XSS. Key detail from the vendor: "Improper neutralization of input during web page generation ('cross‑site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network." This flaw can allow an attacker to inject malicious scripts that masquerade as legitimate SharePoint content, potentially deceiving users and facilitating phishing or other social engineering attacks. The primary impact is deception and the potential for further exploitation based on user interaction with the spoofed content.

Affected Systems

Affected products are Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, and Microsoft SharePoint Server Subscription Edition. Specific version numbers are not provided in the CVE data, so all listed product lines are considered impacted.

Risk and Exploitability

The CVSS score of 8.1 indicates high severity. EPSS is reported as <1%, suggesting a low likelihood of current exploitation, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a remote web‑based XSS where an attacker supplies untrusted input to a SharePoint page that is rendered to users, producing spoofed content or phishing interfaces. The risk is significant for environments that expose SharePoint sites to untrusted input or users with elevated privileges.

Generated by OpenCVE AI on March 17, 2026 at 00:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check Microsoft for a security update or patch for the affected SharePoint products using the Microsoft Security Update Guide link.
  • Apply the available patch or upgrade to a fixed version when it becomes available.
  • Monitor SharePoint logs for suspicious input or injection attempts.
  • Apply web application firewalls or content‑security policies to mitigate XSS if a patch cannot be applied immediately.

Generated by OpenCVE AI on March 17, 2026 at 00:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 13 Mar 2026 20:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:microsoft:sharepoint_server:2016:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:*

Wed, 11 Mar 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft sharepoint Server Subscription Edition
Vendors & Products Microsoft sharepoint Server Subscription Edition

Tue, 10 Mar 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 10 Mar 2026 17:30:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
Title Microsoft SharePoint Server Spoofing Vulnerability
First Time appeared Microsoft
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
Weaknesses CWE-79
CPEs cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2016:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2019:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Sharepoint Server Sharepoint Server 2016 Sharepoint Server 2019 Sharepoint Server Subscription Edition
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-03-27T22:32:51.929Z

Reserved: 2026-02-11T15:52:13.909Z

Link: CVE-2026-26105

cve-icon Vulnrichment

Updated: 2026-03-10T18:39:55.765Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-10T18:18:38.473

Modified: 2026-03-13T20:44:57.800

Link: CVE-2026-26105

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-20T14:34:25Z

Weaknesses