Description
Improper access control in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Published: 2026-07-14
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability stems from improper access control within Microsoft SharePoint, specifically Office SharePoint, allowing a user with existing authorized access to perform spoofing across the network. This flaw is a form of authentication bypass (CWE‑284) that enables an attacker to impersonate other users or services. The report does not describe additional consequences such as phishing or session hijacking, so only the spoofing capability is supported by the provided data.

Affected Systems

Affected installations include Microsoft SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition. No specific patch versions are listed in the advisory, so all current deployments of these products are potentially vulnerable until Microsoft releases an update.

Risk and Exploitability

The CVSS score of 5.4 indicates a moderate impact. The EPSS score is reported as less than 1%, implying a low likelihood of exploitation at the present time. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker must already possess authorized SharePoint access; thus the threat is most relevant to compromised internal accounts or malicious insiders. While the risk remains moderate, the lack of an immediate patch emphasizes the need for monitoring and review of permission scopes.

Generated by OpenCVE AI on August 1, 2026 at 09:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Microsoft security updates for SharePoint as soon as they become available.
  • Reassess and restrict SharePoint permission scopes to eliminate over‑privileged accounts.
  • Implement network monitoring and anomaly detection to identify spoofing attempts.

Generated by OpenCVE AI on August 1, 2026 at 09:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description Improper access control in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Title Microsoft SharePoint Server Spoofing Vulnerability
First Time appeared Microsoft
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
Weaknesses CWE-284
CPEs cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2016:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2019:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Sharepoint Server Sharepoint Server 2016 Sharepoint Server 2019
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-03T22:57:32.884Z

Reserved: 2026-06-19T13:53:31.988Z

Link: CVE-2026-56157

cve-icon Vulnrichment

Updated: 2026-07-14T18:50:14.518Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T09:45:03Z

Weaknesses