Description
Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Published: 2026-09-08
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

This vulnerability is an improper access control flaw (CWE‑284) that allows an attacker with authorized access to the SharePoint environment to execute arbitrary code over the network. The flaw can result in full compromise of the affected SharePoint instance, enabling the attacker to modify or exfiltrate data, gain control over hosted applications, or pivot to other systems on the same network. The impact covers confidentiality, integrity, and availability due to the ability to run code with the privileges of the SharePoint service account.

Affected Systems

Microsoft SharePoint Server Subscription Edition is affected. No specific version information was provided, so all installations of the product that match the CNA listing are potentially vulnerable.

Risk and Exploitability

The vulnerability carries a CVSS score of 8.8, classifying it as high severity. EPSS data is not available, and the flaw is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is network‑based access that leverages valid credentials or permissions within the SharePoint environment. The attacker must first be authenticated or otherwise authorized; no exploitation can occur from an unauthenticated attacker alone.

Generated by OpenCVE AI on September 8, 2026 at 20:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft security update for SharePoint Server Subscription Edition as soon as it becomes available.
  • Restrict network and application access to the SharePoint server, enforcing least privilege for all user accounts that can interact with SharePoint.
  • Configure audit logging and monitor logs for anomalous execution patterns or unauthorized access attempts to detect exploitation early.

Generated by OpenCVE AI on September 8, 2026 at 20:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Title Microsoft Office SharePoint Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft sharepoint Server
Weaknesses CWE-284
CPEs cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*
Vendors & Products Microsoft
Microsoft sharepoint Server
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Sharepoint Server
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:33:28.489Z

Reserved: 2026-08-03T20:44:03.597Z

Link: CVE-2026-69273

cve-icon Vulnrichment

Updated: 2026-09-09T10:00:43.808Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:18:40.297

Modified: 2026-09-09T17:24:59.533

Link: CVE-2026-69273

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T00:45:17Z

Weaknesses