Description
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Published: 2026-06-09
Score: 4.6 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability results from insufficient input neutralization during web page generation in Microsoft SharePoint. An attacker who has valid credentials can inject malicious scripts that are executed in other users’ browsers, allowing the attacker to impersonate legitimate users or alter the appearance of SharePoint pages. The impact is primarily spoofing, which could be leveraged for social engineering or undisclosed data access within the organization.

Affected Systems

The affected products are Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, and Microsoft SharePoint Server Subscription Edition. No specific patch levels or version numbers beyond these product families are listed.

Risk and Exploitability

The CVSS score of 4.6 indicates a moderate severity level. Since the attacker must first be authenticated, the attack vector is limited to users with authorized access, though any such user could act remotely through the web interface. EPSS data is currently unavailable, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no widespread exploitation is known. Nonetheless, an authenticated attacker can exploit the XSS flaw to modify page content for other users, leading to spoofing scenarios that could facilitate further attacks. The risk can be mitigated by applying the official Microsoft security update.

Generated by OpenCVE AI on June 9, 2026 at 19:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft security update that addresses CVE-2026-45479 for the appropriate SharePoint Server release.
  • Restrict privileged SharePoint access to only users who truly need it, and review account permissions to prevent abuse of authenticated accounts.
  • Implement a strict Content Security Policy and enforce proper input validation on SharePoint pages, following Microsoft’s guidance to reduce XSS exposure.

Generated by OpenCVE AI on June 9, 2026 at 19:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 10 Jun 2026 11:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft sharepoint Server Subscription Edition
Vendors & Products Microsoft sharepoint Server Subscription Edition

Tue, 09 Jun 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 09 Jun 2026 17:15:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Title Microsoft SharePoint Server Spoofing Vulnerability
First Time appeared Microsoft
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
Weaknesses CWE-79
CPEs cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2016:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2019:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
References
Metrics cvssV3_1

{'score': 4.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Sharepoint Server Sharepoint Server 2016 Sharepoint Server 2019 Sharepoint Server Subscription Edition
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-06-09T21:49:40.965Z

Reserved: 2026-05-12T16:07:22.616Z

Link: CVE-2026-45479

cve-icon Vulnrichment

Updated: 2026-06-09T20:07:11.416Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-06-09T17:17:22.263

Modified: 2026-06-09T19:32:51.440

Link: CVE-2026-45479

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-10T11:15:05Z

Weaknesses