Description
Insufficiently protected credentials in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Published: 2026-08-11
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Microsoft SharePoint Server arises from credentials that are insufficiently protected, enabling an authorized attacker to perform spoofing over the network. The primary impact is that the attacker can impersonate a legitimate user or service, leading to unauthorized access or manipulation of SharePoint data. The weakness corresponds to CWE-522, which relates to insufficient protection of credentials.

Affected Systems

Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, and Microsoft SharePoint Server Subscription Edition are affected. Detailed version information beyond these product lines is not provided.

Risk and Exploitability

With a CVSS score of 6.5, the vulnerability is considered moderate. The EPSS score of less than 1% indicates a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an internal network scenario where an authorized user’s credentials are exposed; this inference is based on the description. Because the attacker must already be authorized, the exploitability depends on the depth of existing privileges.

Generated by OpenCVE AI on August 12, 2026 at 15:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the Microsoft security update for CVE-2026-62839 from the Microsoft Security Response Center.
  • Ensure that SharePoint credentials are stored using strong encryption or hardware security modules, following best practices to mitigate CWE-522.
  • Restrict network access to the SharePoint server to trusted internal users, enforce multi‑factor authentication, and disable legacy authentication protocols that expose credentials.

Generated by OpenCVE AI on August 12, 2026 at 15:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft sharepoint Server Subscription Edition
Vendors & Products Microsoft sharepoint Server Subscription Edition

Thu, 13 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:microsoft:sharepoint_server:2016:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:*

Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description Insufficiently protected credentials in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Title Microsoft SharePoint Server Spoofing Vulnerability
First Time appeared Microsoft
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
Weaknesses CWE-522
CPEs cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2016:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2019:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Sharepoint Server Sharepoint Server 2016 Sharepoint Server 2019 Sharepoint Server Subscription Edition
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-31T20:08:08.864Z

Reserved: 2026-07-14T21:10:38.083Z

Link: CVE-2026-62839

cve-icon Vulnrichment

Updated: 2026-08-13T13:45:07.923Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:18:37.453

Modified: 2026-08-13T14:17:03.850

Link: CVE-2026-62839

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T12:30:23Z

Weaknesses
  • CWE-522

    Insufficiently Protected Credentials