Description
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Published: 2026-07-14
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from improper neutralization of user input during generation of web pages in Microsoft SharePoint, a classic cross‑site scripting flaw (CWE‑79). An attacker who is already authorized on the SharePoint instance can inject crafted scripts or HTML that will be rendered on the page for other users, enabling them to perform spoofing such as displaying messages that appear to come from the system or other users and potentially deceiving administrators or end‑users.

Affected Systems

Microsoft identifies the affected products as SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition. The vendor did not provide a sub‑version list; any installation of these releases is considered vulnerable.

Risk and Exploitability

Based on the description, it is inferred that the attack vector would generally require the attacker to hold authenticated access to the SharePoint environment; exploiting it may involve creating or modifying content in a site that other users will view. The CVSS score of 7.3 reflects a high impact and moderate to high exploitability. However, the EPSS score is below 1%, indicating a very low current likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on July 31, 2026 at 07:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the Microsoft security update released for CVE‑2026‑55021.
  • Verify that SharePoint’s input sanitization settings are enabled and that scripts are not allowed in user‑generated content.
  • Apply least‑privilege access controls so that only trusted administrators can create or edit site pages that may contain user input.

Generated by OpenCVE AI on July 31, 2026 at 07:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Title Microsoft SharePoint Server Spoofing Vulnerability
First Time appeared Microsoft
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
Weaknesses CWE-79
CPEs cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2016:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2019:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Sharepoint Server Sharepoint Server 2016 Sharepoint Server 2019
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-03T22:56:55.310Z

Reserved: 2026-06-16T14:12:44.284Z

Link: CVE-2026-55021

cve-icon Vulnrichment

Updated: 2026-07-14T19:18:34.659Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T07:15:03Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')