Impact
The vulnerability arises from the deserialization of untrusted data within Microsoft Office SharePoint services. An attacker who can supply crafted input over the network could trigger the deserialization routine and cause arbitrary code execution with the privileges of the SharePoint process. The weakness is classified as CWE‑502, which signifies that the application trusts and processes data from untrusted sources without adequate protection. This flaw allows an unauthorized attacker to trigger code execution on the host, potentially enabling system compromise.
Affected Systems
Affected systems include Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, and Microsoft SharePoint Server Subscription to the deserialization flaw until the official update that addresses CVE‑2026‑50522 is applied.
Risk and Exploitability
With a CVSS score of 9.8, this issue is considered critical. The EPSS score of 76% indicates that a substantial portion of vulnerable configurations may be targeted in the near future. It is listed in the CISA KEV catalog, indicating that attackers could leverage this flaw to compromise the host or pivot to other systems. Exploitation requires the attacker to supply malicious input over an authenticated or unauthenticated channel to the SharePoint service, which is consistent with the inferred network‑based attack vector.
OpenCVE Enrichment