Description
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
Published: 2026-06-09
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a cross‑site scripting flaw arising from insufficient neutralization of user input in SharePoint web page generation. This flaw allows an unauthenticated attacker to inject malicious code that browsers render as part of legitimate SharePoint pages, enabling them to spoof the appearance or identity of the site. The attacker can thereby deceive visitors, potentially facilitating phishing or defacement. No remote code execution is possible; the impact is confined to the web‑application layer and the integrity of the site’s content.

Affected Systems

Microsoft SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition are all affected. Any installation of these product lines, regardless of service pack or patch level, remains vulnerable until a Microsoft update is applied.

Risk and Exploitability

The CVSS score of 5.4 marks the vulnerability as moderate. The EPSS score of less than 1% indicates a low, but non‑zero, likelihood of exploitation in the wild. The flaw can be triggered by an unauthorized attacker who supplies malicious input to a vulnerable part of the SharePoint site; the exact attack vector is not detailed but is inferred to involve publicly accessible input that is not properly sanitized. Once the injection succeeds, every user that renders the affected page will experience the spoofed content. Because the vulnerability is purely a web‑application issue, it does not expose the server to arbitrary code execution, but it can support broader social‑engineering attacks such as credential harvesting. Microsoft has not catalogued this vulnerability in the CISA KEV database.

Generated by OpenCVE AI on July 24, 2026 at 16:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft SharePoint update released for CVE‑2026‑45453.
  • Restrict editing and content‑creation rights to trusted users and enforce the principle of least privilege on SharePoint sites.
  • Implement strict input validation and output encoding for all user‑generated content, and deploy a Content Security Policy to block inline scripts.
  • Segment SharePoint servers from external networks using firewalls or VLANs to limit exposure to the web application.

Generated by OpenCVE AI on July 24, 2026 at 16:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 08 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

Wed, 10 Jun 2026 20:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:microsoft:sharepoint_server:2016:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:*

Wed, 10 Jun 2026 11:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft sharepoint Enterprise Server 2016
Microsoft sharepoint Server Subscription Edition
Vendors & Products Microsoft sharepoint Enterprise Server 2016
Microsoft sharepoint Server Subscription Edition

Tue, 09 Jun 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 09 Jun 2026 17:15:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Title Microsoft SharePoint Server Spoofing Vulnerability
First Time appeared Microsoft
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
Weaknesses CWE-79
CPEs cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2016:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2019:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Sharepoint Enterprise Server 2016 Sharepoint Server Sharepoint Server 2016 Sharepoint Server 2019 Sharepoint Server Subscription Edition
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-15T20:09:05.873Z

Reserved: 2026-05-12T16:06:43.096Z

Link: CVE-2026-45453

cve-icon Vulnrichment

Updated: 2026-06-09T20:04:06.276Z

cve-icon NVD

Status : Analyzed

Published: 2026-06-09T17:17:19.407

Modified: 2026-06-10T20:32:41.143

Link: CVE-2026-45453

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-24T17:00:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')