Impact
The vulnerability involves improper neutralization of input during web page generation—a cross‑site scripting flaw—in Microsoft Office SharePoint, permitting an unauthorized attacker to perform spoofing over a network. An attacker who submits malicious content can have it rendered on SharePoint pages, enabling spoofed content or deceptive actions. The flaw does not provide direct server control or elevated privileges, but the injected script may trick users into interacting with malicious content, harvesting credentials, or altering submitted data. The description indicates that the attacker injects harmful code into SharePoint pages or content that is delivered to browsers over the network.
Affected Systems
Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, and Microsoft SharePoint Server Subscription Edition are affected. The advisory does not specify affected or fixed version ranges, so any installation that has not applied the CVE‑2026‑45464 update remains at risk.
Risk and Exploitability
The CVSS score of 5.4 labels the issue as moderately severe, while the EPSS score of <1 % indicates a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Based on the description it is inferred that an attacker can inject malicious scripts into SharePoint pages or content, which are then rendered in client browsers, enabling spoofing of content. The likely attack vector is remote, with the attacker only needing to edit pages or add content; no elevated privileges are required. This spoofing could mislead users into interacting with malicious content and potentially compromise credentials or data integrity.
OpenCVE Enrichment