Description
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
Published: 2026-08-06
Score: 9.6 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a server‑side request forgery (SSRF) that enables an unauthenticated attacker to provoke the SharePoint Online service to send requests to arbitrary internal or external targets, thereby performing network spoofing. The SSRF flaw can expose sensitive internal resources, facilitate lateral movement, or allow the attacker to exfiltrate data or request privileged information that the service would normally restrict.

Affected Systems

Microsoft SharePoint Online is affected; no specific version details are provided beyond the product designation. The vulnerability impacts all deployments of the identified Microsoft SharePoint Online service that are reachable from the Internet.

Risk and Exploitability

The CVSS score of 9.6 signifies a high‑severity flaw. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is the public SharePoint Online endpoints; an attacker can inject a crafted URL to cause the service to request internal resources. The exploitation requires no privileged access, relying only on the ability to send an HTTP request to the vulnerable service.

Generated by OpenCVE AI on August 7, 2026 at 01:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft patch or update released for CVE‑2026‑70332 as described in the Microsoft security advisory
  • Configure SharePoint Online and any connected networking infrastructure to restrict outbound requests from SharePoint to only trusted destinations
  • Monitor outbound request logs and outbound traffic patterns for anomalous or unexpected destinations to detect potential exploitation attempts

Generated by OpenCVE AI on August 7, 2026 at 01:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Description Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
Title Microsoft Office SharePoint Spoofing Vulnerability
First Time appeared Microsoft
Microsoft sharepoint Online
Weaknesses CWE-918
CPEs cpe:2.3:a:microsoft:sharepoint_online:*:*:*:*:enterprise:*:*:*
Vendors & Products Microsoft
Microsoft sharepoint Online
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Sharepoint Online
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-06T23:22:08.981Z

Reserved: 2026-08-04T00:04:56.036Z

Link: CVE-2026-70332

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T01:30:03Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)