Description
Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
Published: 2026-04-14
Score: 6.5 Medium
EPSS: 24.2% Moderate
KEV: Yes
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper input validation in Microsoft SharePoint Server permits an attacker to supply crafted network traffic that the system interprets as a valid identity, enabling unauthorized spoofing. This flaw allows the attacker to impersonate a legitimate user or service without valid credentials, potentially granting access to protected resources or functions. The weakness is a classic input validation failure (CWE‑20).

Affected Systems

Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, and Microsoft SharePoint Server Subscription Edition are impacted. Current releases of these versions may be affected, but no specific sub‑versions or patch levels are identified.

Risk and Exploitability

The CVSS score of 6.5 reflects moderate severity, and the EPSS score of 24% indicates a relatively high probability of exploitation. The vulnerability is listed in the CISA KEV catalog, confirming that it has been used in the wild. Attackers can exploit the flaw remotely by sending crafted input over the network to the SharePoint services without prior credentials or system access, making any network‑exposed SharePoint deployment a high risk.

Generated by OpenCVE AI on June 18, 2026 at 09:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy the Microsoft security update for CVE‑2026‑32201 as documented in the Microsoft Security Update Guide.
  • Restart SharePoint services or reboot the servers if the update requires it.
  • Monitor authentication and audit logs for signs of spoofing attempts.

Generated by OpenCVE AI on June 18, 2026 at 09:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 28 May 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo

Wed, 15 Apr 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft sharepoint Server Subscription Edition
Vendors & Products Microsoft sharepoint Server Subscription Edition

Tue, 14 Apr 2026 19:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:microsoft:sharepoint_server:2016:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:*

Tue, 14 Apr 2026 18:30:00 +0000

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'active', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Apr 2026 17:45:00 +0000

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2026-04-14T00:00:00+00:00', 'dueDate': '2026-04-28T00:00:00+00:00'}


Tue, 14 Apr 2026 17:30:00 +0000

Type Values Removed Values Added
Description Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
Title Microsoft SharePoint Server Spoofing Vulnerability
First Time appeared Microsoft
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
Weaknesses CWE-20
CPEs cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2016:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2019:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:F/RL:O/RC:C'}


Subscriptions

Microsoft Sharepoint Server Sharepoint Server 2016 Sharepoint Server 2019 Sharepoint Server Subscription Edition
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-06-19T16:08:51.311Z

Reserved: 2026-03-11T01:49:58.658Z

Link: CVE-2026-32201

cve-icon Vulnrichment

Updated: 2026-04-14T17:26:37.680Z

cve-icon NVD

Status : Analyzed

Published: 2026-04-14T18:17:27.160

Modified: 2026-06-17T10:35:20.103

Link: CVE-2026-32201

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-18T09:15:16Z

Weaknesses