Description
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
Published: 2026-08-06
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a cross‑site scripting (XSS) flaw that allows an unauthenticated attacker to inject malicious input into web page generation, resulting in spoofing over the network. This can compromise user experience and potentially redirect or falsify content presented to users, thereby undermining the integrity of the service.

Affected Systems

Microsoft SharePoint Online is affected; no specific version details are provided beyond the product designation. The vulnerability impacts all deployments of the identified Microsoft SharePoint Online service that are reachable from the Internet.

Risk and Exploitability

The CVSS score of 9.6 signifies a high‑severity flaw. EPSS is reported as < 1%, indicating a low but non‑zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is client‑side input fed into SharePoint Online’s web page rendering. Exploitation requires no privileged access, relying only on the ability to submit malicious content to the vulnerable service.

Generated by OpenCVE AI on August 7, 2026 at 16:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft patch or update released for CVE‑2026‑70332 as described in the Microsoft security advisory
  • Implement input validation and encoding (e.g., output escaping or content security policy) on all user‑supplied content in SharePoint Online
  • Monitor web application logs for XSS‑related anomalies and investigate any unexpected script execution attempts

Generated by OpenCVE AI on August 7, 2026 at 16:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 07 Aug 2026 15:00:00 +0000

Type Values Removed Values Added
Description Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
Weaknesses CWE-918 CWE-79

Fri, 07 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Description Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
Title Microsoft Office SharePoint Spoofing Vulnerability
First Time appeared Microsoft
Microsoft sharepoint Online
Weaknesses CWE-918
CPEs cpe:2.3:a:microsoft:sharepoint_online:*:*:*:*:enterprise:*:*:*
Vendors & Products Microsoft
Microsoft sharepoint Online
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Sharepoint Online
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-29T16:24:53.815Z

Reserved: 2026-08-04T00:04:56.036Z

Link: CVE-2026-70332

cve-icon Vulnrichment

Updated: 2026-08-07T15:35:29.981Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-07T00:16:41.040

Modified: 2026-08-07T17:45:01.200

Link: CVE-2026-70332

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T16:30:15Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')