Description
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Published: 2026-05-12
Score: 8.8 High
EPSS: 32.7% Moderate
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authorized attacker who can send network traffic to a Microsoft Office SharePoint server may exploit unsafe deserialization of untrusted data. This vulnerability can allow the attacker to execute arbitrary code on the SharePoint server. Based on the description, it is inferred that such code execution could enable the attacker to influence the server's confidentiality, integrity, or availability by running code with the privileges of the web service process.

Affected Systems

Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, and Microsoft SharePoint Server Subscription Edition are affected. No specific version exclusions were listed, so all current builds of these products are considered vulnerable.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity, and the EPSS score of 33% suggests a relatively high likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector requires an authenticated user who can generate network traffic to the SharePoint server. Once executed, the attacker can potentially gain full control of the server.

Generated by OpenCVE AI on August 24, 2026 at 22:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft security update addressing CVE-2026-33112 from the Microsoft Update Catalog.
  • Restrict network access to SharePoint servers, ensuring only trusted administrative hosts can reach the endpoints.
  • Enforce strict role-based access control so that only users with minimal required permissions can upload or modify data that might trigger the deserialization scenario.

Generated by OpenCVE AI on August 24, 2026 at 22:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 13 May 2026 21:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:microsoft:sharepoint_server:2016:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:*

Wed, 13 May 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft sharepoint Server Subscription Edition
Vendors & Products Microsoft sharepoint Server Subscription Edition

Tue, 12 May 2026 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 12 May 2026 17:30:00 +0000

Type Values Removed Values Added
Description Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Title Microsoft SharePoint Server Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
Weaknesses CWE-502
CPEs cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2016:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2019:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Sharepoint Server Sharepoint Server 2016 Sharepoint Server 2019 Sharepoint Server Subscription Edition
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-10T15:13:19.175Z

Reserved: 2026-03-17T20:15:23.720Z

Link: CVE-2026-33112

cve-icon Vulnrichment

Updated: 2026-05-12T19:20:38.149Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-12T18:17:03.687

Modified: 2026-06-17T10:36:57.957

Link: CVE-2026-33112

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T23:00:06Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data