Description
Missing authentication for critical function in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
Published: 2026-08-11
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a missing authentication check in a critical function of Microsoft SharePoint Server. This flaw allows an attacker who is already authenticated to the network to gain higher privileges within SharePoint, effectively elevating their access level without proper authorization. The flaw does not provide arbitrary code execution but compromises confidentiality, integrity, and availability by enabling unauthorized users to perform privileged operations.

Affected Systems

The vulnerability affects Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, and Microsoft SharePoint Server Subscription Edition. No specific version numbers are listed, indicating that all current releases of these products are potentially impacted.

Risk and Exploitability

With a CVSS score of 8.8, the vulnerability is considered high severity. The EPSS score is not available, and it is not listed in the CISA KEV catalog, suggesting that there is no known widespread exploitation at the time of analysis. However, because the flaw permits privileged escalation over an internal network, the likely attack vector is local or within the organization’s trusted network, and an attacker only needs to be authenticated to the network to exploit it.

Generated by OpenCVE AI on August 12, 2026 at 13:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft SharePoint Server security update that addresses the missing authentication flaw.
  • Audit user roles and permissions in SharePoint to ensure that least‑privilege best practices are enforced.
  • Implement network segmentation or firewall rules to limit access to SharePoint critical endpoints to trusted hosts only.

Generated by OpenCVE AI on August 12, 2026 at 13:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft sharepoint Server Subscription Edition
Vendors & Products Microsoft sharepoint Server Subscription Edition

Thu, 13 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:microsoft:sharepoint_server:2016:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:*

Tue, 11 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description Missing authentication for critical function in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
Title Microsoft SharePoint Server Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
Weaknesses CWE-306
CPEs cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2016:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2019:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Sharepoint Server Sharepoint Server 2016 Sharepoint Server 2019 Sharepoint Server Subscription Edition
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-31T20:07:31.950Z

Reserved: 2026-07-20T20:25:40.977Z

Link: CVE-2026-64921

cve-icon Vulnrichment

Updated: 2026-08-11T18:27:01.756Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:18:53.463

Modified: 2026-08-13T13:37:46.633

Link: CVE-2026-64921

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T12:31:16Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function