Description
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Published: 2026-08-11
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Server‑side request forgery (SSRF) in Microsoft SharePoint Server allows an authorized attacker to cause the server to issue HTTP requests to arbitrary addresses over a network, effectively spoofing outbound traffic. This vulnerability is identified as CWE‑918.

Affected Systems

The vulnerability affects Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, and Microsoft SharePoint Server Subscription Edition. No specific minor patch levels are listed, but the flaw exists in all listed product versions.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate impact level. The EPSS score of less than 1% suggests that exploitation attempts are rare. The vulnerability is not listed in the CISA KEV catalog. Because it requires authorized access to a SharePoint site, the attacker must first be authenticated before the SSRF can be leveraged to cause the server to send forged requests.

Generated by OpenCVE AI on August 12, 2026 at 15:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft patch available at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58639.
  • Restrict outbound connections from SharePoint servers by configuring firewall or proxy rules to allow only approved destinations.
  • Segment the SharePoint environment from critical internal resources and monitor for abnormal outbound traffic patterns that could indicate SSRF exploitation.

Generated by OpenCVE AI on August 12, 2026 at 15:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft sharepoint Enterprise Server 2016
Microsoft sharepoint Server Subscription Edition
Vendors & Products Microsoft sharepoint Enterprise Server 2016
Microsoft sharepoint Server Subscription Edition

Wed, 12 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:microsoft:sharepoint_server:2016:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:*

Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Title Microsoft SharePoint Server Spoofing Vulnerability
First Time appeared Microsoft
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
Weaknesses CWE-918
CPEs cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2016:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2019:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Sharepoint Enterprise Server 2016 Sharepoint Server Sharepoint Server 2016 Sharepoint Server 2019 Sharepoint Server Subscription Edition
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-31T20:08:08.293Z

Reserved: 2026-07-01T21:14:44.618Z

Link: CVE-2026-58639

cve-icon Vulnrichment

Updated: 2026-08-12T17:04:33.325Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:18:05.137

Modified: 2026-08-12T20:17:45.487

Link: CVE-2026-58639

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T12:30:24Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)