Description
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Published: 2026-09-08
Score: 7.3 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability arises from improper neutralization of user input during web page generation in Microsoft Office SharePoint. The flaw permits an attacker who has authorized access to the SharePoint environment to inject malicious content that can deceive users, effectively enabling spoofing attacks. Because the injected script runs in the victim's browser context, the attacker can modify the appearance or behavior of pages without their knowledge, thereby compromising the integrity of the information displayed.

Affected Systems

The issue affects Microsoft SharePoint Server Subscription Edition. No specific version range was provided in the CNA data, so any deployment of this product edition that has not installed the latest security update may be vulnerable.

Risk and Exploitability

The CVSS score of 7.3 indicates a high risk severity. The exploit requires the attacker to have authorized access or privileges sufficient to add or edit web pages. Once those conditions are met, the attacker can craft malicious input that is not properly sanitized. Because the exploitation vector is internal or requires authenticated user rights, the likelihood remains limited to users with sufficient permissions, and it is not listed in CISA's KEV catalog. However, the high score and the potential for deceptive attacks underscore the need for timely remediation.

Generated by OpenCVE AI on September 8, 2026 at 20:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the security update for Microsoft SharePoint Server Subscription Edition referenced by the Microsoft Security Response Center update guide.
  • Restrict SharePoint editor and content publishing permissions to trusted users only, and enforce least‑privilege access controls.
  • Review and sanitize any custom web parts or third‑party content to ensure inputs are properly encoded before rendering.

Generated by OpenCVE AI on September 8, 2026 at 20:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Title Microsoft Office SharePoint Spoofing Vulnerability
First Time appeared Microsoft
Microsoft sharepoint Server
Weaknesses CWE-79
CPEs cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*
Vendors & Products Microsoft
Microsoft sharepoint Server
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Sharepoint Server
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-08T23:40:27.187Z

Reserved: 2026-08-03T20:57:58.964Z

Link: CVE-2026-69417

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-09-08T18:19:04.697

Modified: 2026-09-08T19:22:18.470

Link: CVE-2026-69417

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T21:00:12Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')