Description
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
Published: 2026-08-11
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An attacker can inject unsanitized input into SharePoint pages, creating a cross‑site scripting flaw that enables website spoofing over the network. The attacker could alter page content or mimic legitimate users, leading to defacement, phishing, or other malicious impersonation activity. This vulnerability is categorized as a cross‑site scripting flaw.

Affected Systems

The affected products are Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019 and Microsoft SharePoint Server Subscription Edition. Version details are not specified in the data, but any installation of the mentioned SharePoint editions could be impacted.

Risk and Exploitability

The CVSS score is 9.3, indicating high severity; the EPSS score is less than 1%, so exploitation is considered unlikely but still possible. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is over a network, where an unauthenticated or minimally privileged user could supply malicious input to a SharePoint page. The exploitation requires only the ability to deliver crafted input to the vulnerable SharePoint instance.

Generated by OpenCVE AI on August 12, 2026 at 18:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the official patch for CVE-2026-70306 provided by Microsoft.
  • If patching cannot be performed immediately, restrict network access to the SharePoint servers and block suspicious inbound traffic.
  • Configure input validation on all public SharePoint pages to remove or encode user-supplied data before rendering.

Generated by OpenCVE AI on August 12, 2026 at 18:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:microsoft:sharepoint_server:2016:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:*

Tue, 11 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
Title Microsoft Office SharePoint Spoofing Vulnerability
First Time appeared Microsoft
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
Weaknesses CWE-79
CPEs cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2016:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2019:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Sharepoint Server Sharepoint Server 2016 Sharepoint Server 2019
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-31T20:07:57.663Z

Reserved: 2026-08-04T00:01:20.931Z

Link: CVE-2026-70306

cve-icon Vulnrichment

Updated: 2026-08-11T17:55:43.262Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:19:07.970

Modified: 2026-08-16T19:17:24.953

Link: CVE-2026-70306

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T19:00:08Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')