Description
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Published: 2026-08-11
Score: 8.8 High
EPSS: 1.9% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a flaw in deserialization of untrusted data in Microsoft Office SharePoint. An authenticated attacker, who can log into SharePoint, can send crafted data that is deserialized by the system and consequently execute arbitrary code on the SharePoint server. The weakness is identified as CWE‑502 and allows the attacker to compromise confidentiality, integrity, and availability of the affected SharePoint installation.

Affected Systems

Microsoft SharePoint Server 2016 Enterprise Edition, Microsoft SharePoint Server 2019, and Microsoft SharePoint Server Subscription Edition.\"

Risk and Exploitability

This vulnerability has a CVSS score of 8.8, indicating high severity. The EPSS score is 2%, and the flaw is not listed in the CISA Known Exploited Vulnerabilities catalog. The likely attack path requires network access to the SharePoint server and an authenticated session. Based on the description, it is inferred that the attacker must have valid credentials to send the malicious data, after which the server will execute code in its own context.

Generated by OpenCVE AI on August 13, 2026 at 01:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft security update for SharePoint Server 2016, 2019, or Subscription Edition as published on the Microsoft Security Response Center.
  • Restrict SharePoint access to trusted users and enforce least‑privilege policies to limit the ability of an attacker to act as an authorized user.
  • Review custom or third‑party components that perform deserialization of user‑controlled data and implement proper validation or replace them with safer alternatives.

Generated by OpenCVE AI on August 13, 2026 at 01:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft sharepoint Enterprise Server 2016
Microsoft sharepoint Server Subscription Edition
Vendors & Products Microsoft sharepoint Enterprise Server 2016
Microsoft sharepoint Server Subscription Edition

Tue, 11 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:microsoft:sharepoint_server:2016:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:*

Tue, 11 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Title Microsoft SharePoint Server Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
Weaknesses CWE-502
CPEs cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2016:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2019:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Sharepoint Enterprise Server 2016 Sharepoint Server Sharepoint Server 2016 Sharepoint Server 2019 Sharepoint Server Subscription Edition
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-31T20:07:23.214Z

Reserved: 2026-07-20T20:25:40.975Z

Link: CVE-2026-64901

cve-icon Vulnrichment

Updated: 2026-08-11T19:07:46.207Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:18:50.937

Modified: 2026-08-12T05:19:10.050

Link: CVE-2026-64901

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T01:45:02Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data