Description
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
Published: 2026-08-11
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a server‑side request forgery that allows an attacker with legitimate access to the SharePoint Server to elevate their privileges by manipulating outbound requests. The flaw can lead to unauthorized access to internal resources or the acquisition of higher‑level permissions within the SharePoint environment. This is a high‑severity flaw (CVSS score 8.8).

Affected Systems

Microsoft SharePoint Server Subscription Edition is impacted. No specific affected versions are listed in the CVE data, so the risk applies to all deployments of this product until a patch is applied.

Risk and Exploitability

The EPSS score is reported as less than 1%, indicating that, as of now, the probability of exploitation is low and no known exploits have been observed. The flaw is not currently catalogued in the CISA Known Exploit Vulnerability catalog. The likely attack vector requires an authorized user to send a crafted request that exploits the server’s outbound request capability, leading to privilege escalation over the internal network. The CVSS score underscores the seriousness of successful exploitation, but the low EPSS suggests opportunistic attackers may deprioritise this vulnerability.

Generated by OpenCVE AI on August 12, 2026 at 14:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply all available Microsoft SharePoint Server updates through Microsoft Update or the Update Catalog to mitigate the SSRF flaw.
  • Configure outbound firewall rules to restrict the SharePoint server from reaching internal endpoints that are not explicitly required for its operation, thereby limiting the impact of an SSRF attack.
  • Enable comprehensive logging and monitoring of outbound requests from SharePoint, and regularly review logs for anomalous activity that could indicate exploitation attempts.

Generated by OpenCVE AI on August 12, 2026 at 14:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft sharepoint Server Subscription Edition
Vendors & Products Microsoft sharepoint Server Subscription Edition

Tue, 11 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
Title Microsoft SharePoint Server Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft sharepoint Server
Weaknesses CWE-918
CPEs cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*
Vendors & Products Microsoft
Microsoft sharepoint Server
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Sharepoint Server Sharepoint Server Subscription Edition
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-31T20:07:58.203Z

Reserved: 2026-08-04T00:01:20.934Z

Link: CVE-2026-70326

cve-icon Vulnrichment

Updated: 2026-08-11T18:26:53.256Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:19:10.393

Modified: 2026-08-13T13:48:59.617

Link: CVE-2026-70326

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T12:30:35Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)