Description
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
Published: 2026-09-08
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

Microsoft Office SharePoint contains an improper neutralization of special elements used in an SQL command, allowing a SQL injection that can elevate privileges. The vulnerability is classified as CWE-89 and has a CVSS score of 8.8, indicating a serious impact on confidentiality, integrity, and availability for users with elevated access.

Affected Systems

Vendors and products affected include Microsoft SharePoint Server Subscription Edition. No specific version information has been provided, so all versions of this product are potentially impacted until a patch is applied.

Risk and Exploitability

The risk is high, with a CVSS score of 8.8. EPSS data is not available, so the likelihood of exploitation cannot be precisely quantified, and the vulnerability is not listed in the CISA KEV catalog. The attack vector likely requires an authorized user or an authenticated session, as the description states that an authorized attacker can use the flaw to elevate privileges. Lacking further exploitation details, the best estimate is that an attacker who already has legitimate access could abuse the injection to gain higher privileges.

Generated by OpenCVE AI on September 8, 2026 at 23:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest security update for Microsoft SharePoint Server Subscription Edition from the Microsoft Security Response Center
  • Review and reduce user permissions to the principle of least privilege so that authenticated users cannot exploit the SQL injection for privilege escalation
  • Enable comprehensive logging and monitoring to detect suspicious SQL activity and anomalous privilege changes
  • Consider isolating critical SharePoint resources in a segmented network to contain potential lateral movement
  • Validate input for all database queries to ensure proper sanitization and guard against injection attacks

Generated by OpenCVE AI on September 8, 2026 at 23:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
Title Microsoft Office SharePoint Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft sharepoint Server
Weaknesses CWE-89
CPEs cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*
Vendors & Products Microsoft
Microsoft sharepoint Server
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Sharepoint Server
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:32:57.664Z

Reserved: 2026-08-03T21:35:55.263Z

Link: CVE-2026-69716

cve-icon Vulnrichment

Updated: 2026-09-09T10:01:12.084Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:19:43.703

Modified: 2026-09-09T17:14:41.637

Link: CVE-2026-69716

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T14:00:11Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')