Description
Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
Published: 2026-09-08
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Apply Patch
AI Analysis

Impact

Based on the description, it is inferred that the vulnerability permits an attacker who already has authenticated access to Microsoft SharePoint Server Subscription Edition to execute operations with higher privileges than intended. This elevation of privilege can lead to unauthorized manipulation of data and configuration, potentially compromising the confidentiality, integrity, and availability of all assets stored in the SharePoint environment. The weakness is classified as CWE-250, which addresses improper privilege or access control.

Affected Systems

Microsoft SharePoint Server Subscription Edition is affected. No specific version numbers are listed, indicating that all deployments of this product may be vulnerable until a security update is applied.

Risk and Exploitability

With a CVSS score of 8.8, the vulnerability carries a high severity rating. EPSS data is not available and the vulnerability is not listed in CISA KEV, suggesting limited public exploitation evidence. Based on the description, it is inferred that the most likely attack vector requires an attacker to have authorized access to the SharePoint Server; from that position, they can exploit the unnecessary privileges to execute higher‑privilege actions across the network.

Generated by OpenCVE AI on September 8, 2026 at 22:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Microsoft security update for SharePoint Server Subscription Edition as released by Microsoft.
  • Review all service and administrative accounts and reduce privileges to the minimum required for each role, enforcing the principle of least privilege.
  • Implement network segmentation to limit the reach of elevated privileges and isolate the SharePoint environment from other critical systems.

Generated by OpenCVE AI on September 8, 2026 at 22:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft sharepoint Server Subscription Edition
Vendors & Products Microsoft sharepoint Server Subscription Edition

Wed, 09 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
Title Microsoft Office SharePoint Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft sharepoint Server
Weaknesses CWE-250
CPEs cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*
Vendors & Products Microsoft
Microsoft sharepoint Server
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Sharepoint Server Sharepoint Server Subscription Edition
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-30T15:23:27.213Z

Reserved: 2026-08-03T21:03:33.032Z

Link: CVE-2026-69464

cve-icon Vulnrichment

Updated: 2026-09-09T09:54:28.190Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:19:11.560

Modified: 2026-09-09T17:18:36.880

Link: CVE-2026-69464

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T20:52:42Z

Weaknesses
  • CWE-250

    Execution with Unnecessary Privileges