Description
Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Published: 2026-08-11
Score: 4.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper input validation in Microsoft Office SharePoint allows an authorized attacker to spoof information over a network. The flaw can lead to deceptive data presentation or duplicate content, undermining user confidence and possibly giving the attacker the appearance of legitimate content delivery. The weakness is identified as CWE‑20 – Improper Input Validation.

Affected Systems

The vulnerability affects Microsoft SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition. These products are covered by the Microsoft CNA and are impacted until a suitable patch is deployed.

Risk and Exploitability

The CVSS score of 4.6 indicates a moderate severity. The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog. Exploitation requires an authenticated attacker who can submit crafted content to the affected SharePoint instance. The lack of a publicly disclosed exploit suggests the risk remains low, but the moderate base score underscores that the spoofing could result in significant confusion, data integrity issues, or unauthorized content rendering for users who rely on the affected SharePoint deployment.

Generated by OpenCVE AI on August 12, 2026 at 12:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and apply the Microsoft security update that resolves CVE‑2026‑62917 from the Microsoft Security Update Guide for the affected SharePoint versions.
  • Restrict network access to the SharePoint servers to trusted IP ranges or require VPN connectivity to limit exposure to authorized attackers.
  • Monitor SharePoint logs for signs of malformed input or repeated spoofing attempts and investigate any anomalous activity promptly.

Generated by OpenCVE AI on August 12, 2026 at 12:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:microsoft:sharepoint_server:2016:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:*

Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Title Microsoft SharePoint Server Spoofing Vulnerability
First Time appeared Microsoft
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
Weaknesses CWE-20
CPEs cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2016:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2019:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
References
Metrics cvssV3_1

{'score': 4.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Sharepoint Server Sharepoint Server 2016 Sharepoint Server 2019
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-31T20:08:09.430Z

Reserved: 2026-07-14T21:25:21.036Z

Link: CVE-2026-62917

cve-icon Vulnrichment

Updated: 2026-08-13T13:45:43.543Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:18:45.700

Modified: 2026-08-13T14:17:03.963

Link: CVE-2026-62917

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T12:30:03Z

Weaknesses
  • CWE-20

    Improper Input Validation