Description
Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Published: 2026-09-08
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Microsoft SharePoint Server Subscription Edition suffers a missing authorization flaw that permits an authenticated attacker to remotely execute code. The vulnerability arises from insufficient checks on privileged actions, allowing the attacker to trigger arbitrary code on the server. As a result, compromise grants full process execution control, enabling compromise of confidentiality, integrity, and availability of the affected system.

Affected Systems

Vulnerable systems are Microsoft SharePoint Server Subscription Edition instances. Specific affected product versions are not enumerated in the data; administrators should verify against the official Microsoft Security Update guide referenced. All installations that have not applied the latest security update are potentially exposed.

Risk and Exploitability

The CVSS score is 8.8, indicating high severity. The EPSS score is not available, so the current exploitation probability remains unknown. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is over the network from an authenticated user; correct authentication exists but the authorization check is missing. Exploitation requires valid credentials with sufficient privileges but does not require further vulnerabilities.

Generated by OpenCVE AI on September 9, 2026 at 00:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft security update for SharePoint Server Subscription Edition that addresses the missing authorization flaw.
  • Configure firewall or network segmentation to limit external access to SharePoint services to approved IP ranges or internal networks only.
  • Enforce least‑privilege and review identity‑and‑access‑management policies for SharePoint to ensure only authorized personnel have code execution permissions.

Generated by OpenCVE AI on September 9, 2026 at 00:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Title Microsoft Office SharePoint Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft sharepoint Server
Weaknesses CWE-862
CPEs cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*
Vendors & Products Microsoft
Microsoft sharepoint Server
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Sharepoint Server
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:32:59.359Z

Reserved: 2026-08-03T21:35:55.264Z

Link: CVE-2026-69724

cve-icon Vulnrichment

Updated: 2026-09-09T10:01:07.942Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:19:44.593

Modified: 2026-09-09T17:14:15.230

Link: CVE-2026-69724

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T13:45:10Z

Weaknesses