Description
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Published: 2026-09-08
Score: 4.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑site scripting that enables domain spoofing and potential credential theft
Action: Assess Impact
AI Analysis

Impact

Microsoft SharePoint Server Subscription Edition suffers from improper neutralization of user input when generating web pages, leading to a cross‑site scripting vulnerability. An authorized attacker can inject malicious scripts that are served to end users, allowing the attacker to impersonate legitimate content or user identities, carry out phishing attacks, or steal credentials. This flaw compromises the integrity and authenticity of the web interface.

Affected Systems

Affected systems are Microsoft SharePoint Server Subscription Edition installations. No specific version list is provided by the CNA, so any deployed instance that allows content generation without proper input filtering is potentially vulnerable.

Risk and Exploitability

The CVSS score is 4.6, indicating a moderate severity flaw. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known exploitation at this time. The likely attack vector is an authenticated user or application with authorized permissions who can create or edit content on SharePoint; the flaw is triggered when the injected script is rendered to viewers, causing client‑side execution. The risk is primarily to authentication and trust, with potential for credential theft or malicious navigation.

Generated by OpenCVE AI on September 9, 2026 at 00:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any Microsoft SharePoint update that addresses the XSS flaw as soon as it is released by Microsoft.
  • Implement server‑side output encoding (e.g., HTML entity encoding) and strict input validation for all user‑supplied data rendered in SharePoint pages.
  • Deploy a web application firewall configured for XSS detection and monitor for anomalous script injection activity.
  • Enforce least‑privilege access controls for content authors to reduce the likelihood of malicious script injection.

Generated by OpenCVE AI on September 9, 2026 at 00:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft sharepoint Server Subscription Edition
Vendors & Products Microsoft sharepoint Server Subscription Edition

Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Title Microsoft Office SharePoint Spoofing Vulnerability
First Time appeared Microsoft
Microsoft sharepoint Server
Weaknesses CWE-79
CPEs cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*
Vendors & Products Microsoft
Microsoft sharepoint Server
References
Metrics cvssV3_1

{'score': 4.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Sharepoint Server Sharepoint Server Subscription Edition
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:33:00.423Z

Reserved: 2026-08-03T21:28:58.728Z

Link: CVE-2026-69690

cve-icon Vulnrichment

Updated: 2026-09-09T18:53:35.285Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:19:41.197

Modified: 2026-09-09T19:17:41.577

Link: CVE-2026-69690

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T13:00:12Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')