Description
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Published: 2026-08-11
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper neutralization of user‑supplied input during web page generation in Microsoft SharePoint Server enables a cross‑site scripting flaw that can be exploited for user spoofing. The vulnerability allows an attacker to inject script content into SharePoint pages, thereby presenting themselves as a legitimate user to other network users. This is a classic input validation weakness identified as CWE‑79 and could facilitate social‑engineering or malicious code execution when victims load the compromised content in their browsers.

Affected Systems

Microsoft SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition are affected. No specific patch versions are listed beyond the product families, so administrators should review all instances of these SharePoint editions and apply appropriate updates whenever released.

Risk and Exploitability

The CVSS base score of 7.3 indicates high severity, and the EPSS score of less than 1% suggests a very low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be user‑initiated, as an authorized attacker must have rights to create or modify pages—meaning the attacker must be authenticated and possess sufficient privileges to inject the malicious code. Based on the description, it is inferred that the exploit can be carried out over the network when a victim’s browser renders the compromised page.

Generated by OpenCVE AI on August 12, 2026 at 16:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft security update for CVE‑2026‑64900 from the Microsoft Security Update Guide.
  • Restrict users’ ability to add or edit HTML or script in SharePoint pages by disabling custom HTML or using content type restrictions.
  • Implement a robust content‑security policy and enforce input sanitization on all web parts to prevent script injection.

Generated by OpenCVE AI on August 12, 2026 at 16:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft sharepoint Server Subscription Edition
Vendors & Products Microsoft sharepoint Server Subscription Edition

Wed, 12 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
CPEs cpe:2.3:a:microsoft:sharepoint_server:2016:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:*

Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Title Microsoft SharePoint Server Spoofing Vulnerability
First Time appeared Microsoft
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
CPEs cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2016:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2019:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Sharepoint Server Sharepoint Server 2016 Sharepoint Server 2019 Sharepoint Server Subscription Edition
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-31T20:07:21.536Z

Reserved: 2026-07-20T20:25:40.975Z

Link: CVE-2026-64900

cve-icon Vulnrichment

Updated: 2026-08-12T15:57:39.461Z

cve-icon NVD

Status : Modified

Published: 2026-08-11T17:18:50.827

Modified: 2026-08-19T15:17:44.317

Link: CVE-2026-64900

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T12:31:19Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')