Impact
Improper authentication in Microsoft SharePoint Server enables an attacker who has already authenticated to elevate privileges, resulting in the ability to impersonate higher‑privileged accounts and gain administrative access to site content, compromising data integrity and availability.
Affected Systems
Microsoft SharePoint Server deployments, including Enterprise Server 2016, Server 2019, and Subscription Edition, are affected; the advisory does not specify a particular patch level, so all current versions that have not applied an update remain at risk.
Risk and Exploitability
The CVSS score of 8.8 classifies this as a high severity flaw. No EPSS data are available, and the vulnerability is not listed in the CISA KEV catalog, indicating no confirmed public exploit. The attack vector is likely network‑based, requiring an authenticated attacker who can send requests to the vulnerable SharePoint service; once authenticated, the flaw allows elevation to unrestricted administrative control, posing significant risk until mitigated.
OpenCVE Enrichment