Impact
An incorrect authorization check in Microsoft SharePoint Server permits an attacker who is already authenticated to alter data over the network. The flaw allows modification of configuration or content without proper privilege validation, resulting in a loss of data integrity and unauthorized modifications to SharePoint items. No other capabilities such as arbitrary code execution or denial of service are stated in the provided information.
Affected Systems
Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, and Microsoft SharePoint Server Subscription Edition are affected by this vulnerability.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and the EPSS score of < 1% suggests low likelihood of exploitation at present. The vulnerability is classified as CWE‑863 (Authorization Bypass). It is not listed in CISA’s KEV catalog. The likely attack vector is over the network; an authenticated attacker can exploit the improper authorization mechanism to change data. Given the moderate severity and low exploitation probability, the overall risk is moderate to low, but updating is recommended to preserve data integrity.
OpenCVE Enrichment