Description
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Published: 2026-08-11
Score: 8.8 High
EPSS: 1.5% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. This flaw, identified as CWE‑502, enables remote code execution on affected SharePoint Server 2016, 2019, and Subscription Edition instances, potentially granting the attacker full control over the underlying host.

Affected Systems

The vulnerability affects Microsoft SharePoint Server 2016, Microsoft SharePoint Server 2019, and Microsoft SharePoint Server Subscription Edition. No specific version constraints are listed, so all current releases are considered affected.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity. The EPSS score of 2% indicates a low but non‑zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The flaw permits deserialization of untrusted data over a network; an authorized attacker with access to the SharePoint environment can send malicious input that the server deserializes, leading to remote code execution.

Generated by OpenCVE AI on August 13, 2026 at 02:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft patch that addresses the deserialization flaw for SharePoint Server 2016, 2019, and Subscription Edition as soon as it is released.
  • Ensure that only authenticated and authorized users can send data to the SharePoint endpoints, applying the principle of least privilege to all SharePoint services.
  • Configure SharePoint’s Input Validation and Data Processing settings to reject or sanitize untrusted data streams, if possible, until a patch is applied.

Generated by OpenCVE AI on August 13, 2026 at 02:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:microsoft:sharepoint_server:2016:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:*

Tue, 11 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in the console component. An attacker who can write to container logs on a managed cluster can inject malicious code into the hub console user's browser session. This occurs when the user views raw pod logs, as the console does not properly escape the log content. Successful exploitation could lead to session hijacking, credential theft, or unauthorized actions performed on behalf of the console user. Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Title console: console: stored DOM XSS via unescaped pod logs in document.write Microsoft SharePoint Server Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
Weaknesses CWE-502
CPEs cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2016:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2019:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
References
Metrics cvssV3_1

{'score': 8.0, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Tue, 11 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat
Redhat console
Vendors & Products Redhat
Redhat console

Tue, 11 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in the console component. An attacker who can write to container logs on a managed cluster can inject malicious code into the hub console user's browser session. This occurs when the user views raw pod logs, as the console does not properly escape the log content. Successful exploitation could lead to session hijacking, credential theft, or unauthorized actions performed on behalf of the console user.
Title console: console: stored DOM XSS via unescaped pod logs in document.write
Weaknesses CWE-79
References
Metrics threat_severity

None

cvssV3_1

{'score': 8.0, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}

threat_severity

Important


Subscriptions

Microsoft Sharepoint Server Sharepoint Server 2016 Sharepoint Server 2019
Redhat Console
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-29T16:24:42.231Z

Reserved: 2026-07-27T19:02:26.601Z

Link: CVE-2026-66805

cve-icon Vulnrichment

Updated: 2026-08-11T17:59:33.703Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:19:01.850

Modified: 2026-08-13T13:41:22.610

Link: CVE-2026-66805

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-10T20:00:00Z

Links: CVE-2026-66805 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T02:30:12Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data

  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')