Description
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Published: 2026-06-09
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The description states that deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. This unsafe deserialization (CWE‑502) provides a means for the attacker to inject or manipulate content, leading to spoofed information presented to users. While CWE‑79 is also listed, the scripting, so that possibility remains inferred rather than confirmed.

Affected Systems

The vulnerability impacts Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, and Microsoft SharePoint Server Subscription Edition. Version information is not specified, so any release prior to the latest security update from Microsoft is potentially affected.

Risk and Exploitability

The description states that deserialization of untrusted data in authorized attacker to perform spoofing over a network. The CVSS score of 5.4 indicates moderate severity. The EPSS score is approximately 0.00937 (<1%), indicating a very low but non‑zero probability of exploitation, and the flaw is not listed in CISA’s KEV catalog, suggesting it is not widely exploited in the wildtrusted data (CWE‑502), and while CWE is listed, the current description does not explicitly mention it. The likely attack vector is web‑based; an attacker must have valid credentials or be able to submit content to the SharePoint instance to trigger the injection. If this condition is met, the attacker can present spoofed content to end users, undermining trust and potentially facilitating further social‑engineering or phishing attacks.

Generated by OpenCVE AI on July 21, 2026 at 18:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft SharePoint Server security update available from the Microsoft Security Response Center.
  • Restrict the set of users who can submit content to the web pages, and enforce least‑privilege policies to minimize the impact of an attacker who gains authorized access.
  • Implement or enforce input validation and output encoding controls on all content that flows from user input to the rendered web pages to prevent cross‑site scripting.

Generated by OpenCVE AI on July 21, 2026 at 18:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 08 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Fri, 12 Jun 2026 15:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
CPEs cpe:2.3:a:microsoft:sharepoint_server:2016:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:*

Wed, 10 Jun 2026 00:00:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft sharepoint Enterprise Server 2016
Microsoft sharepoint Server Subscription Edition
Vendors & Products Microsoft sharepoint Enterprise Server 2016
Microsoft sharepoint Server Subscription Edition

Tue, 09 Jun 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 09 Jun 2026 17:15:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Title Microsoft SharePoint Server Spoofing Vulnerability
First Time appeared Microsoft
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
Weaknesses CWE-502
CPEs cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2016:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2019:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Sharepoint Enterprise Server 2016 Sharepoint Server Sharepoint Server 2016 Sharepoint Server 2019 Sharepoint Server Subscription Edition
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-15T20:10:09.725Z

Reserved: 2026-05-21T20:00:35.245Z

Link: CVE-2026-48560

cve-icon Vulnrichment

Updated: 2026-06-09T17:48:48.329Z

cve-icon NVD

Status : Analyzed

Published: 2026-06-09T17:17:44.633

Modified: 2026-06-12T15:41:27.713

Link: CVE-2026-48560

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T18:45:03Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data

  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')