Description
Incorrect authorization in Microsoft Office SharePoint allows an authorized attacker to perform tampering over a network.
Published: 2026-08-11
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An incorrect authorization check in Microsoft SharePoint Server permits an attacker who is already authenticated to alter data over the network. The flaw allows modification of configuration or content without proper privilege validation, resulting in a loss of data integrity and unauthorized modifications to SharePoint items. No other capabilities such as arbitrary code execution or denial of service are stated in the provided information.

Affected Systems

Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, and Microsoft SharePoint Server Subscription Edition are affected by this vulnerability.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity, and the EPSS score of < 1% suggests low likelihood of exploitation at present. The vulnerability is classified as CWE‑863 (Authorization Bypass). It is not listed in CISA’s KEV catalog. The likely attack vector is over the network; an authenticated attacker can exploit the improper authorization mechanism to change data. Given the moderate severity and low exploitation probability, the overall risk is moderate to low, but updating is recommended to preserve data integrity.

Generated by OpenCVE AI on August 12, 2026 at 17:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the Microsoft security update for SharePoint Server that addresses CVE‑2026‑63512, available via the Microsoft update guide.
  • Enforce multi‑factor authentication for all SharePoint administrative accounts to reduce credential misuse and limit the potential impact of compromised credentials.
  • Apply network segmentation or firewall rules to restrict direct access to SharePoint management and tampering endpoints, ensuring only trusted hosts can reach them.

Generated by OpenCVE AI on August 12, 2026 at 17:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft sharepoint Enterprise Server 2016
Microsoft sharepoint Server Subscription Edition
Vendors & Products Microsoft sharepoint Enterprise Server 2016
Microsoft sharepoint Server Subscription Edition

Wed, 12 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:microsoft:sharepoint_server:2016:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:*

Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description Incorrect authorization in Microsoft Office SharePoint allows an authorized attacker to perform tampering over a network.
Title Microsoft SharePoint Server Tampering Vulnerability
First Time appeared Microsoft
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
Weaknesses CWE-863
CPEs cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2016:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2019:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Sharepoint Enterprise Server 2016 Sharepoint Server Sharepoint Server 2016 Sharepoint Server 2019 Sharepoint Server Subscription Edition
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-31T20:04:12.067Z

Reserved: 2026-07-16T22:05:22.740Z

Link: CVE-2026-63512

cve-icon Vulnrichment

Updated: 2026-08-12T14:07:31.006Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:18:45.950

Modified: 2026-08-12T15:18:06.880

Link: CVE-2026-63512

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T11:23:21Z

Weaknesses