Description
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
Published: 2026-08-11
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a server‑side request forgery (SSRF) in Microsoft SharePoint that allows an authenticated attacker to instruct the server to send requests to internal endpoints. By exploiting this flaw, the attacker can elevate their privileges within the SharePoint environment, potentially gaining full control over the affected SharePoint instance. The weakness is categorised as CWE‑918, indicating that the server trusts user input and can be directed to external or internal resources without proper validation.

Affected Systems

Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019 and the SharePoint Server Subscription Edition are the products affected by this vulnerability. Specific version numbers are not listed, so any installation of these products should be evaluated against the available patch set.

Risk and Exploitability

The CVSS score of 8.8 classifies this issue as high severity. The EPSS score is less than 1 %, implying that the probability of this vulnerability being actively exploited in the wild is currently low, and it is not present in the CISA KEV catalog. The likely attack vector requires an attacker to have valid SharePoint credentials – an authorized user who can trigger the SSRF by submitting a crafted request. From there, the server can be coaxed into reaching internal addresses, allowing the attacker to perform privileged actions that they would not normally be able to execute.

Generated by OpenCVE AI on August 12, 2026 at 14:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft SharePoint security update for CVE‑2026‑70324 as published in the Microsoft Security Response Center.
  • Configure firewall or proxy rules to restrict SharePoint’s outbound HTTP(S) traffic to approved destinations, thereby reducing the SSRF surface area.
  • Enforce least‑privilege for SharePoint user accounts and remove any unnecessary permissions to limit the impact of a successful privilege escalation.
  • Enable and review logging of outbound requests from SharePoint to detect anomalous activity that may indicate exploitation attempts.

Generated by OpenCVE AI on August 12, 2026 at 14:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:microsoft:sharepoint_server:2016:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:*

Wed, 12 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft sharepoint Enterprise Server 2016
Microsoft sharepoint Server Subscription Edition
Vendors & Products Microsoft sharepoint Enterprise Server 2016
Microsoft sharepoint Server Subscription Edition

Tue, 11 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
Title Microsoft SharePoint Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
Weaknesses CWE-918
CPEs cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2016:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2019:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft sharepoint Server
Microsoft sharepoint Server 2016
Microsoft sharepoint Server 2019
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Sharepoint Enterprise Server 2016 Sharepoint Server Sharepoint Server 2016 Sharepoint Server 2019 Sharepoint Server Subscription Edition
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-31T20:06:12.103Z

Reserved: 2026-08-04T00:01:20.934Z

Link: CVE-2026-70324

cve-icon Vulnrichment

Updated: 2026-08-11T19:21:52.403Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:19:10.143

Modified: 2026-08-13T13:48:16.690

Link: CVE-2026-70324

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T15:15:02Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)