Description
Relative path traversal in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
Published: 2026-08-11
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A relative path traversal flaw exists in Microsoft SharePoint Server that permits an attacker with authorized credentials to read files and directories outside those intended for access. The vulnerability enables the disclosure of internal data over the network, potentially exposing sensitive information and compromising confidentiality. It is classified as a medium severity problem, as reflected by the CVSS score of 6.5.

Affected Systems

The flaw affects Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, and Microsoft SharePoint Server Subscription Edition. No specific sub‑version ranges are listed, so all releases within these product families are potentially impacted.

Risk and Exploitability

The EPSS score indicates a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The attack requires the attacker already be authenticated to the SharePoint environment, implying that it hinges on privilege escalation or compromised credentials. Given the moderate severity and the low exploitation probability, the risk is considered moderate but still warrants careful review of access controls and timely application of vendor fixes.

Generated by OpenCVE AI on August 12, 2026 at 17:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Review the Microsoft security advisory linked above and apply the latest SharePoint Server update that addresses the path traversal fix.
  • Enforce least privilege on user accounts and restrict SharePoint access to only those who require it; consider network segmentation to isolate the SharePoint servers from other critical workloads.
  • Audit SharePoint logging to detect abnormal file request patterns and implement monitoring to alert on potential traversal attempts.

Generated by OpenCVE AI on August 12, 2026 at 17:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft sharepoint Enterprise Server 2016
Microsoft sharepoint Server Subscription Edition
Vendors & Products Microsoft sharepoint Enterprise Server 2016
Microsoft sharepoint Server Subscription Edition

Tue, 11 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:microsoft:sharepoint_server:2016:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:*

Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description Relative path traversal in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
Title Microsoft SharePoint Server Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
Weaknesses CWE-23
CPEs cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2016:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2019:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Sharepoint Enterprise Server 2016 Sharepoint Server Sharepoint Server 2016 Sharepoint Server 2019 Sharepoint Server Subscription Edition
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-31T20:04:11.057Z

Reserved: 2026-07-14T21:10:38.083Z

Link: CVE-2026-62837

cve-icon Vulnrichment

Updated: 2026-08-11T20:38:34.569Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:18:37.327

Modified: 2026-08-11T21:17:41.957

Link: CVE-2026-62837

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T11:23:22Z

Weaknesses
  • CWE-23

    Relative Path Traversal