Description
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Published: 2026-09-08
Score: 7.3 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability arises from the failure to neutralize user‑supplied data when generating web pages in Microsoft SharePoint. An attacker with authorized access can embed malicious scripts that trick users into believing the content originates from a legitimate source, effectively creating a spoofing environment that can be used for phishing or defacement.

Affected Systems

Microsoft SharePoint Server Subscription Edition is affected. No specific version numbers are listed in the CNA data, so all deployed instances of this product edition are considered vulnerable until the issued patch is applied.

Risk and Exploitability

With a CVSS score of 7.3 the issue is considered high severity. The EPSS score is not available, and the vulnerability is not included in the CISA KEV catalog, indicating no known widespread exploitation. The likely attack vector requires an attacker that already has authorized privileges within the SharePoint environment; a compromised or privileged user could inject the malicious payload into a page.

Generated by OpenCVE AI on September 8, 2026 at 20:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft security update for SharePoint Server Subscription Edition that addresses the XSS flaw.
  • Configure SharePoint to encode or sanitize all user input before rendering it on pages, following the guidelines of CWE‑79 to prevent script injection.
  • Limit page modification permissions to trusted administrators only and review role‑based access controls to reduce the risk of accidental or malicious injection.

Generated by OpenCVE AI on September 8, 2026 at 20:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Title Microsoft Office SharePoint Spoofing Vulnerability
First Time appeared Microsoft
Microsoft sharepoint Server
Weaknesses CWE-79
CPEs cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*
Vendors & Products Microsoft
Microsoft sharepoint Server
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Sharepoint Server
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-08T23:40:26.102Z

Reserved: 2026-08-03T20:57:58.963Z

Link: CVE-2026-69402

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-09-08T18:19:02.543

Modified: 2026-09-08T19:22:18.470

Link: CVE-2026-69402

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T21:00:12Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')