Description
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Published: 2026-06-09
Score: 4.6 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Microsoft Office SharePoint has an XSS weakness that occurs when the system fails to neutralize certain user-controlled input during web page rendering. An attacker who can legitimately interact with SharePoint—such as a user with content editing or administrative privileges—can inject malicious script fragments into pages or elements that the platform then reflects back to users without proper encoding. This capability enables the attacker to display false information or fake administrative responses (spoofing) over the network, potentially deceiving users into revealing credentials or executing unintended actions. The vulnerability has a CVSS score of 4.6, indicating moderate severity. The exploitation likelihood is not publicly available, and it has not been observed in the CISA KEV catalog. Exploitation requires authentic access within a SharePoint environment and the ability to inject content that is subsequently displayed to other users.

Affected Systems

The flaw affects Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, and Microsoft SharePoint Subscription Edition. No specific affected release dates or version ranges were listed in the CNA data, so any installation of these product lines may be vulnerable until a patch is applied.

Risk and Exploitability

The CVSS rating reflects that the attack vector is remote, local access or network access with authenticated privileges is needed, and the impact is primarily on integrity for the web pages presented. Since the EPSS score is not available, it is unclear how frequently the flaw is being exploited in the wild. The lack of KEV inclusion suggests no large-scale exploitation has yet been reported. Nonetheless, an attacker with the necessary privileges can leverage the XSS to trick legitimate users into performing actions within the SharePoint environment, potentially leading to data tampering or credential theft.

Generated by OpenCVE AI on June 9, 2026 at 19:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Microsoft security update for CVE-2026-45462, obtainable from the Microsoft Security Update Guide or via Windows Update for SharePoint Server 2016, 2019, and Subscription Edition.
  • Deploy a Web Application Firewall (WAF) on the SharePoint front‑end to detect and block script tags, JavaScript payloads, and other potentially harmful HTML elements in URLs, form fields, and custom web part content.
  • Enforce strict input validation and output encoding for all user‑supplied or content‑editable fields, and disable or sanitize execution of script tags in custom web parts in accordance with CWE‑79 best practices.

Generated by OpenCVE AI on June 9, 2026 at 19:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 10 Jun 2026 11:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft sharepoint Enterprise Server 2016
Microsoft sharepoint Server Subscription Edition
Vendors & Products Microsoft sharepoint Enterprise Server 2016
Microsoft sharepoint Server Subscription Edition

Tue, 09 Jun 2026 17:15:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Title Microsoft SharePoint Server Spoofing Vulnerability
First Time appeared Microsoft
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
Weaknesses CWE-79
CPEs cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2016:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2019:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
References
Metrics cvssV3_1

{'score': 4.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Sharepoint Enterprise Server 2016 Sharepoint Server Sharepoint Server 2016 Sharepoint Server 2019 Sharepoint Server Subscription Edition
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-06-09T21:50:39.469Z

Reserved: 2026-05-12T16:06:43.097Z

Link: CVE-2026-45462

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-06-09T17:17:20.577

Modified: 2026-06-09T19:32:51.440

Link: CVE-2026-45462

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-10T11:15:05Z

Weaknesses