Description
Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
Published: 2026-09-08
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Microsoft Office SharePoint allows an attacker who already has authorized credentials to misuse unnecessary privileges and read sensitive information over the network. This represents a privilege escalation flaw (CWE‑250) that results in data disclosure; it does not provide code execution or denial of service.

Affected Systems

The affected product is Microsoft SharePoint Server Subscription Edition. No specific affected version ranges are listed in the advisory, but the issue applies to any installation that exposes SharePoint services to clients.

Risk and Exploitability

The CVSS v3 base score is 6.5, signifying medium severity. The EPSS score is unavailable, so real‑world exploitation probability cannot be determined, and the vulnerability is not listed in the CISA KEV catalog. An attacker would need legitimate access to a SharePoint site and would exploit the privilege misuse path to obtain data via the SharePoint web interfaces or APIs, which can be reached remotely over the network.

Generated by OpenCVE AI on September 8, 2026 at 20:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any Microsoft security update that addresses CVE-2026-69409 for SharePoint Server Subscription Edition.
  • If no update is currently available, restrict SharePoint users’ permissions and disable unnecessary web parts or features that could expose data.
  • Enforce network segmentation to limit remote access to SharePoint services to trusted administrative hosts.

Generated by OpenCVE AI on September 8, 2026 at 20:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
Title Microsoft Office SharePoint Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft sharepoint Server
Weaknesses CWE-250
CPEs cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*
Vendors & Products Microsoft
Microsoft sharepoint Server
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Sharepoint Server
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-08T20:07:51.080Z

Reserved: 2026-08-03T20:57:58.963Z

Link: CVE-2026-69409

cve-icon Vulnrichment

Updated: 2026-09-08T20:07:44.468Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-09-08T18:19:03.733

Modified: 2026-09-08T20:17:50.213

Link: CVE-2026-69409

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T21:00:12Z

Weaknesses
  • CWE-250

    Execution with Unnecessary Privileges