Description
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Published: 2026-08-11
Score: 8.8 High
EPSS: 1.3% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Deserialization of untrusted data in Microsoft SharePoint allows an authorized attacker to execute code on the server over the network. The flaw is a deserialization vulnerability (CWE-502) that can be leveraged to run arbitrary code with the privileges of the SharePoint service. This results in a complete loss of confidentiality, integrity, and availability for the affected SharePoint instance.

Affected Systems

Microsoft SharePoint Server Subscription Edition is affected. No specific version range is provided, so any installation of this product that has not applied the latest Microsoft update is vulnerable.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity, and the EPSS score of 1% suggests that exploitation is unlikely but possible. The vulnerability is not listed in CISA KEV, implying no known large-scale exploitation yet. The attack requires network access to the SharePoint service and authentication or a privileged account that can upload or cause parsing of malicious data. Since the flaw involves deserialization, attackers may craft payloads that are interpreted during normal SharePoint processing, resulting in remote code execution.

Generated by OpenCVE AI on August 13, 2026 at 01:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft security update for SharePoint Server Subscription Edition from the Microsoft Security Response Center.
  • Restrict network access to the SharePoint server to trusted IP ranges and enforce strict authentication; consider implementing least‑privilege user roles to reduce the attack surface.
  • Monitor SharePoint logs for unusual deserialization or code execution activity and investigate any anomalous behavior promptly.

Generated by OpenCVE AI on August 13, 2026 at 01:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft sharepoint Server Subscription Edition
Vendors & Products Microsoft sharepoint Server Subscription Edition

Tue, 11 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Title Microsoft SharePoint Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft sharepoint Server
Weaknesses CWE-502
CPEs cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*
Vendors & Products Microsoft
Microsoft sharepoint Server
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Sharepoint Server Sharepoint Server Subscription Edition
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-31T20:06:06.039Z

Reserved: 2026-08-04T00:01:20.933Z

Link: CVE-2026-70321

cve-icon Vulnrichment

Updated: 2026-08-11T18:27:20.759Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:19:09.760

Modified: 2026-08-13T13:47:40.600

Link: CVE-2026-70321

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T01:45:02Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data