Description
Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
Published: 2026-09-08
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Based on the description, it is inferred that the vulnerability permits an attacker who already has authenticated access to Microsoft SharePoint Server Subscription Edition to execute operations with higher privileges than intended. This elevation of privilege can lead to unauthorized manipulation of data and configuration, potentially compromising the confidentiality, integrity, and availability of all assets stored in the SharePoint environment. The weakness is classified as CWE-250, which addresses improper privilege or access control.

Affected Systems

Microsoft SharePoint Server Subscription Edition is affected. No specific version numbers are listed, indicating that all deployments of this product may be vulnerable until a security update is applied.

Risk and Exploitability

With a CVSS score of 8.8, the vulnerability carries a high severity rating. EPSS data is not available and the vulnerability is not listed in CISA KEV, suggesting limited public exploitation evidence. Based on the description, it is inferred that the most likely attack vector requires an attacker to have authorized access to the SharePoint Server; from that position, they can exploit the unnecessary privileges to execute higher‑privilege actions across the network.

Generated by OpenCVE AI on September 8, 2026 at 22:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft security update for SharePoint Server Subscription Edition as released by Microsoft.
  • Review all service and administrative accounts and reduce privileges to the minimum required for each role, enforcing the principle of least privilege.
  • Implement network segmentation to limit the reach of elevated privileges and isolate the SharePoint environment from other critical systems.

Generated by OpenCVE AI on September 8, 2026 at 22:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
Title Microsoft Office SharePoint Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft sharepoint Server
Weaknesses CWE-250
CPEs cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*
Vendors & Products Microsoft
Microsoft sharepoint Server
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Sharepoint Server
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-08T23:40:36.536Z

Reserved: 2026-08-03T21:03:33.032Z

Link: CVE-2026-69464

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T18:19:11.560

Modified: 2026-09-08T18:39:34.660

Link: CVE-2026-69464

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T22:30:06Z

Weaknesses
  • CWE-250

    Execution with Unnecessary Privileges