Description
Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
Published: 2026-08-11
Score: 8.1 High
EPSS: 2.9% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. The vulnerability is a typical CWE‑20 flaw and can lead to full compromise of the affected SharePoint server, giving the attacker control over the system and the ability to exfiltrate data or pivot to other assets.

Affected Systems

Affected products include Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, and Microsoft SharePoint Server Subscription Edition. No specific version ranges are provided in the CNA data; all releases of these products are potentially vulnerable.

Risk and Exploitability

The CVSS score of 8.1 signifies a serious severity. The EPSS score is 3%, indicating a moderate likelihood of exploitation, but the lack of a KEV listing suggests that active exploitation has not yet been reported. Inferred from the description, the attack vector is remote, requiring network connectivity to the SharePoint servers. Given the high severity and potential for exploitation, the risk to organizations that run these servers remains significant.

Generated by OpenCVE AI on August 24, 2026 at 16:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any available Microsoft security update for SharePoint to address the input validation flaw
  • Restrict network access to SharePoint endpoints, allowing only trusted hosts and users to reach the server
  • Enable and monitor audit logging and intrusion detection to detect any attempts to exploit the vulnerability

Generated by OpenCVE AI on August 24, 2026 at 16:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft sharepoint Server Subscription Edition
Vendors & Products Microsoft sharepoint Server Subscription Edition

Thu, 13 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:microsoft:sharepoint_server:2016:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:*

Tue, 11 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
Title Microsoft SharePoint Server Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
Weaknesses CWE-20
CPEs cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2016:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2019:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Sharepoint Server Sharepoint Server 2016 Sharepoint Server 2019 Sharepoint Server Subscription Edition
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-31T20:04:13.676Z

Reserved: 2026-07-16T22:05:22.740Z

Link: CVE-2026-63520

cve-icon Vulnrichment

Updated: 2026-08-11T18:27:46.552Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:18:47.377

Modified: 2026-08-13T13:38:30.453

Link: CVE-2026-63520

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T17:00:04Z

Weaknesses
  • CWE-20

    Improper Input Validation