Description
External control of file name or path in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Published: 2026-07-14
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Microsoft SharePoint Server systems are vulnerable to an external control of file name or path flaw that allows a user with authorized write access to craft file names or paths that are interpreted by the server as originating from another source. This weakness enables an attacker to display content to other users or administrators as if it were legitimate, potentially leading to the delivery of malicious content or the spread of misinformation. The flaw does not give the attacker the ability to execute arbitrary code but provides a means to subvert user trust, which can be leveraged in phishing or social engineering attacks within the network.

Affected Systems

Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019 and Microsoft SharePoint Server Subscription Edition are affected lines is present in the core file name/path handling code and no specific version ranges are identified in the advisory.

Risk and Exploitability

The CVSS score of 6.5 indicates a medium severity. The EPSS score of less than 1% suggests that exploitation is currently unlikely in the wild, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw requires an attacker to hold authorized credentials that allow file upload or linking, the attack surface is limited to authenticated users with such privileges. The attacker can exploit the lack of proper sanitization by uploading or referencing a file with a crafted name or path that displays as if it were from.

Generated by OpenCVE AI on July 31, 2026 at 09:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the Microsoft security update for CVE-2026-54108 as provided on the Microsoft Security Response Center
  • Limit permissions for uploading or linking external files to reduce the ability of authorized users to craft malicious paths
  • Implement stricter input validation on file names and paths, ensuring only permitted characters and directories are accepted, and audit related logs for suspicious activity

Generated by OpenCVE AI on July 31, 2026 at 09:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Description External control of file name or path in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Title Microsoft SharePoint Server Spoofing Vulnerability
First Time appeared Microsoft
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
Weaknesses CWE-73
CPEs cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2016:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2019:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Sharepoint Server Sharepoint Server 2016 Sharepoint Server 2019
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-30T20:22:44.614Z

Reserved: 2026-06-11T20:33:37.835Z

Link: CVE-2026-54108

cve-icon Vulnrichment

Updated: 2026-07-14T18:07:38.381Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T09:30:05Z

Weaknesses
  • CWE-73

    External Control of File Name or Path