Description
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Published: 2026-08-11
Score: 8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Microsoft Office SharePoint is vulnerable to an improper neutralization of input during web page generation, a classic cross‑site scripting flaw. The flaw permits an authorized attacker to inject malicious content that is rendered as legitimate SharePoint pages, enabling spoofing of legitimate users and systems over the network. The impact is primarily deceptive, allowing the attacker to impersonate a trusted source, potentially leading to phishing, credential theft, or further lateral movement when users interact with the spoofed content.

Affected Systems

The vulnerability affects Microsoft SharePoint Server 2019 and Microsoft SharePoint Server Subscription Edition. Only these product lines are listed as impacted; no specific version numbers are provided beyond the product family.

Risk and Exploitability

The CVSS score of 8 indicates a high severity level, and the EPSS score of 0.0049 (less than 1%) indicates a very low, but non‑zero, exploitation probability. The vulnerability is not listed in the CISA KEV catalog, so a known exploit has not been documented yet. The attack requires the attacker to already possess authorized access to a SharePoint instance. Once that condition is met, the XSS flaw can be leveraged to serve crafted pages that masquerade as legitimate content, potentially tricking users into divulging credentials or executing other malicious actions.

Generated by OpenCVE AI on August 12, 2026 at 18:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest security update for Microsoft SharePoint Server 2019 and the Subscription Edition as published in the Microsoft Advisory for CVE‑2026‑57105.
  • Enable SharePoint’s built‑in cross‑site scripting protection by enabling the XSS Filter and enforcing a strong Content Security Policy to limit executable scripts.
  • Monitor user interactions for suspicious navigation patterns and review logs for anomalous rendering activities.

Generated by OpenCVE AI on August 12, 2026 at 18:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft sharepoint Server Subscription Edition
Vendors & Products Microsoft sharepoint Server Subscription Edition

Tue, 11 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:*

Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Title Microsoft Office SharePoint Spoofing Vulnerability
First Time appeared Microsoft
Microsoft sharepoint Server
Microsoft sharepoint Server 2019
Weaknesses CWE-79
CPEs cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2019:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft sharepoint Server
Microsoft sharepoint Server 2019
References
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Sharepoint Server Sharepoint Server 2019 Sharepoint Server Subscription Edition
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-31T20:04:09.437Z

Reserved: 2026-06-23T18:29:51.054Z

Link: CVE-2026-57105

cve-icon Vulnrichment

Updated: 2026-08-11T19:57:33.589Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:18:04.740

Modified: 2026-08-12T05:17:56.507

Link: CVE-2026-57105

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T11:23:24Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')