Description
Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Published: 2026-06-09
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. The flaw arises because the system fails to sanitize particular special elements before rendering them, enabling a user with the necessary SharePoint privileges to inject malicious content that will be displayed as if it originated from a trusted source. The result is the attacker’s ability to masquerade as another user or entity within the SharePoint environment, creating opportunities for misattribution and higher social engineering risk.

Affected Systems

Microsoft SharePoint Server 2019 and Microsoft SharePoint Server Subscription Edition are vulnerable and considered at risk until a vendor patch is applied.

Risk and Exploitability

The CVSS score of 7.3 reflects a high severity for compromised SharePoint usage. The EPSS score of < 1% indicates a very low probability that this flaw will be actively exploited in the wild. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred from the description: it requires an authenticated SharePoint user with sufficient privileges to inject malicious content that will be displayed to others, resulting in spoofing over the network.

Generated by OpenCVE AI on August 2, 2026 at 01:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft update that addresses this injection flaw (see the Microsoft Security Advisory for CVE-2026-47634).
  • Configure SharePoint to enforce strict output encoding for all user‑supplied or external content to mitigate cross‑site scripting (CWE-79).
  • Restrict editing permissions to the minimum necessary and review audit logs for anomalous content changes to reduce the likelihood of malicious injection.

Generated by OpenCVE AI on August 2, 2026 at 01:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 08 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Wed, 10 Jun 2026 21:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
CPEs cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:*

Wed, 10 Jun 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 10 Jun 2026 01:15:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft sharepoint Server Subscription Edition
Vendors & Products Microsoft sharepoint Server Subscription Edition

Tue, 09 Jun 2026 17:15:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Title Microsoft SharePoint Server Spoofing Vulnerability
First Time appeared Microsoft
Microsoft sharepoint Server
Microsoft sharepoint Server 2019
Weaknesses CWE-74
CPEs cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2019:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft sharepoint Server
Microsoft sharepoint Server 2019
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Sharepoint Server Sharepoint Server 2019 Sharepoint Server Subscription Edition
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-28T22:19:36.830Z

Reserved: 2026-05-19T20:12:27.070Z

Link: CVE-2026-47634

cve-icon Vulnrichment

Updated: 2026-06-10T13:46:29.060Z

cve-icon NVD

Status : Analyzed

Published: 2026-06-09T17:17:35.300

Modified: 2026-06-10T20:49:24.287

Link: CVE-2026-47634

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T02:00:13Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')