Description
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Published: 2026-07-14
Score: 4.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an instance of improper input neutralization during web page generation, classified as a cross‑site scripting flaw (CWE‑79). A user who is already authorized to use the SharePoint server can inject malicious content that is later rendered by the web interface. The injected payload can appear as legitimate content to other users, effectively allowing the attacker to spoof the appearance or identity of the site or its components over the network.

Affected Systems

Affected installations include Microsoft SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition. These are the SharePoint Server products listed by the CNA, with no specific version ranges provided in the data; any installation of the listed products may be vulnerable if the corresponding security update has not been applied.

Risk and Exploitability

The CVSS score of 4.6 indicates moderate severity, and the EPSS score of less than 1% suggests a very low probability of exploitation in the wild. The vulnerability is not currently listed in the CISA KEV catalog. The flaw requires that the attacker already have legitimate access to the SharePoint environment; from that position, the attacker can inject XSS code that other users will interpret, enabling spoofing of site content or user interfaces. The limited attack surface and low exploitation likelihood reduce the overall risk, but the ability to masquerade as legitimate content remains a concern for environments where insider threats are a possibility.

Generated by OpenCVE AI on July 31, 2026 at 07:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the latest SharePoint Server release that includes the fix for CVE-2026-55030
  • Ensure that all user–generated content is properly sanitized and encoded to prevent XSS, following SharePoint security best practices
  • Restrict or disable JavaScript execution from untrusted content sources and monitor for abnormal script injection attempts

Generated by OpenCVE AI on July 31, 2026 at 07:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Title Microsoft SharePoint Server Spoofing Vulnerability
First Time appeared Microsoft
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
Weaknesses CWE-79
CPEs cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2016:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2019:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
References
Metrics cvssV3_1

{'score': 4.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Sharepoint Server Sharepoint Server 2016 Sharepoint Server 2019
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-03T22:56:57.538Z

Reserved: 2026-06-16T14:12:44.285Z

Link: CVE-2026-55030

cve-icon Vulnrichment

Updated: 2026-07-14T18:11:46.355Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T07:15:03Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')