Description
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Published: 2026-07-14
Score: 4.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is an instance of improper neutralization of user supplied input during SharePoint web page rendering. An attacker who already has legitimate credentials can insert a malicious payload into content that is later served to other users. When that content is displayed, the browser executes the script, enabling the attacker to modify the visual appearance of pages or embed deceptive elements. The impact is a spoofing attack that can mislead users into believing they are interacting with authentic SharePoint content, without granting any new privileges or bypassing authentication.

Affected Systems

Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, and Microsoft SharePoint Server Subscription Edition. The issue applies to all released versions of these products where user‑controlled content is rendered without proper encoding.

Risk and Exploitability

The CVSS score of 4.6 classifies the vulnerability as moderate. The EPSS score of less than 1 % indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to have valid credentials to add or edit content and to be able to inject a crafted script. Once those conditions are met, the script runs in the victim’s browser, enabling spoofing but not compromising overall system integrity or confidentiality.

Generated by OpenCVE AI on July 31, 2026 at 07:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft security update for SharePoint Server (see the Microsoft Security Response Center advisory for CVE‑2026‑55020).
  • Configure SharePoint’s Content Protection settings to enforce strict input validation and output encoding for all user‑generated content.
  • Deploy a Web Application Firewall that blocks or sanitizes cross‑site scripting payloads before they reach the SharePoint application.

Generated by OpenCVE AI on July 31, 2026 at 07:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 16 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Title Microsoft SharePoint Server Spoofing Vulnerability
First Time appeared Microsoft
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
Weaknesses CWE-79
CPEs cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2016:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2019:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
References
Metrics cvssV3_1

{'score': 4.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Sharepoint Server Sharepoint Server 2016 Sharepoint Server 2019
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-03T22:56:54.832Z

Reserved: 2026-06-16T14:12:44.284Z

Link: CVE-2026-55020

cve-icon Vulnrichment

Updated: 2026-07-16T14:01:51.035Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T07:15:03Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')