Description
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Published: 2026-07-14
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Microsoft Office SharePoint arises from improper neutralization of user input when generating web a classic cross‑site scripting (XSS) weakness that lets an attacker craft malicious content that the server will render. Because the vulnerability only affects users who already have authorized access, the attacker can alter the appearance of SharePoint pages, potentially creating a spoofed interface or misleading users. The primary impact is the ability to impersonate legitimate content or branding, which can undermine trust and facilitate social‑engineering attacks within the organization.

Affected Systems

Microsoft SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition are affected. No specific revision numbers are supplied in the data, so any installed instance of these product lines is assumed to be vulnerable unless confirmed otherwise.

Risk and Exploitability

The CVSS score of 7.3 indicates a medium‑to‑high severity flaw. The EPSS score is reported as less than 1%, suggesting that exploitation is unlikely but still possible, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw requires the attacker to already have authorized access, the attack vector is internal and likely limited to users or processes within the same network or domain. Exploiting the XSS condition would involve supplying crafted input that the server fails to sanitize, leading to spoofed content being displayed to other authenticated users.

Generated by OpenCVE AI on July 31, 2026 at 07:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Microsoft security update that eliminates the XSS flaw in all SharePoint Server 2016, 2019, and Subscription Edition products
  • Restrict user permissions so that only trusted accounts can supply content that is rendered as part of web pages
  • Deploy a web application firewall or equivalent filtering to block suspicious script injections in the form of malicious HTML or JavaScript

Generated by OpenCVE AI on July 31, 2026 at 07:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Title Microsoft SharePoint Server Spoofing Vulnerability
First Time appeared Microsoft
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
Weaknesses CWE-79
CPEs cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2016:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2019:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Sharepoint Server Sharepoint Server 2016 Sharepoint Server 2019
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-30T20:26:16.768Z

Reserved: 2026-06-16T14:13:49.835Z

Link: CVE-2026-55034

cve-icon Vulnrichment

Updated: 2026-07-15T11:00:10.531Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T07:15:03Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')