Description
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Published: 2026-08-11
Score: 8.8 High
EPSS: 1.5% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Deserialization of untrusted data in Microsoft SharePoint Server allows an attacker who is already authorized on the system to execute arbitrary code over the network. The vulnerability is classified as a high severity Remote Code Execution flaw with a CVSS score of 8.8. The weakness, identified as CWE‑502, means that the service blindly processes input that can be crafted to inject malicious content, thereby giving the attacker the ability to take control of the SharePoint host and potentially compromise the confidentiality, integrity, and availability of that server.

Affected Systems

Microsoft SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition are all affected. No specific patch level or sub‑version is listed, so any installation of these products is potentially vulnerable until a vendor‑issued update is applied.

Risk and Exploitability

The threat remains high because the vulnerability can be triggered by a network request from an attacker who possesses valid SharePoint credentials. The EPSS score of 1% indicates a very low but non‑zero probability of exploitation, while the CVSS score denotes a serious impact, and the vulnerability is not listed in CISA’s KEV catalog. An attacker could use the flaw to compromise the SharePoint environment, exfiltrate data, install malware, or pivot to other systems. Because the exploit requires prior authorization, internal attackers or compromised user accounts are the most likely threat actors.

Generated by OpenCVE AI on August 13, 2026 at 02:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Microsoft patch or cumulative update that addresses CVE‑2026‑63514 for SharePoint Server 2016, 2019, or Subscription Edition.
  • If a patch is not yet available, immediately restrict network access to the SharePoint servers to the minimum set of trusted hosts and implement role‑based access controls so that only users who genuinely need to upload/deserialized content can do so.
  • Configure or disable the SharePoint feature that performs the deserialization of untrusted data, or add input validation/sanitization to ensure that only trusted data is processed.

Generated by OpenCVE AI on August 13, 2026 at 02:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft sharepoint Enterprise Server 2016
Microsoft sharepoint Server Subscription Edition
Vendors & Products Microsoft sharepoint Enterprise Server 2016
Microsoft sharepoint Server Subscription Edition

Wed, 12 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:microsoft:sharepoint_server:2016:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:*

Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Title Microsoft SharePoint Server Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
Weaknesses CWE-502
CPEs cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2016:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2019:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Sharepoint Enterprise Server 2016 Sharepoint Server Sharepoint Server 2016 Sharepoint Server 2019 Sharepoint Server Subscription Edition
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-31T20:04:11.542Z

Reserved: 2026-07-16T22:05:22.740Z

Link: CVE-2026-63514

cve-icon Vulnrichment

Updated: 2026-08-12T13:39:56.627Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:18:46.213

Modified: 2026-08-12T14:18:26.360

Link: CVE-2026-63514

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T02:45:03Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data