Impact
Missing authentication for a critical function in Microsoft SharePoint Server allows an attacker to invoke that function without credentials, enabling privilege escalation. The vulnerability is a CWE‑306 type authentication bypass and can let an unauthorized user perform administrative actions normally reserved for privileged accounts.
Affected Systems
Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, and Microsoft SharePoint Server Subscription Edition are all affected. All releases of these products remain vulnerable until a patch is applied, as no narrower version range has been disclosed.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score of 22 % suggests a significant likelihood that attackers will target this flaw. It is listed in the CISA KEV catalog, confirming real‑world exploitation. Based on the description, the vulnerable function can be accessed remotely over a network; an attacker who can reach the SharePoint server can exploit the flaw from within the same domain without prior authentication.
OpenCVE Enrichment