Description
Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Published: 2026-09-08
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an improper access control flaw that allows an authorized attacker to execute code on a Microsoft SharePoint Server Subscription Edition instance over the network. This weakness, classified as CWE-284, can compromise the confidentiality, integrity, and availability of the affected system by providing the attacker with the ability to run arbitrary code with the permissions of the authenticated user.

Affected Systems

Microsoft SharePoint Server Subscription Edition. No specific version range is listed in the current data.

Risk and Exploitability

The flaw carries a CVSS score of 8.8, indicating high severity. Because the EPSS score is not available and the vulnerability is not listed in CISA KEV, the risk assessment relies primarily on the CVSS score and the fact that an attacker must be authorized to exploit it. The likely attack vector is a network‑based exploitation that requires valid user credentials, implying that privileged or misconfigured accounts are the main concern. No public exploit evidence is provided, but the high score suggests that once a CVE is disclosed, attackers will likely develop or seek out exploits.

Generated by OpenCVE AI on September 8, 2026 at 20:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft SharePoint Server Subscription Edition security patch that resolves the access control flaw as announced in the Microsoft security advisory.
  • Reduce account privileges by reviewing SharePoint permissions and ensuring users operate with the least privilege necessary for their role.
  • Restrict network access to the SharePoint endpoint by segmentation or firewall rules, and consider enforcing zero‑trust or VPN access to limit exposure to trusted networks.

Generated by OpenCVE AI on September 8, 2026 at 20:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Title Microsoft Office SharePoint Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft sharepoint Server
Weaknesses CWE-284
CPEs cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*
Vendors & Products Microsoft
Microsoft sharepoint Server
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Sharepoint Server
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:33:29.092Z

Reserved: 2026-08-03T20:44:03.598Z

Link: CVE-2026-69282

cve-icon Vulnrichment

Updated: 2026-09-08T18:59:20.766Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:18:42.693

Modified: 2026-09-09T17:23:26.337

Link: CVE-2026-69282

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T00:30:07Z

Weaknesses