Description
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
Published: 2026-08-11
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is an improper neutralization of user input during the rendering of SharePoint pages, enabling a cross‑site scripting attack. An attacker who already has authorized access can embed malicious scripts into SharePoint content; when a target user views the page, the script runs with the privileges of that user, allowing the attacker to elevate privileges, manipulate data, or move laterally within the network.

Affected Systems

Microsoft SharePoint Server 2019 and Microsoft SharePoint Server Subscription Edition are affected. The vulnerability applies to all versions of these products unless an update has been applied. Exact version ranges are not supplied in the CNA data.

Risk and Exploitability

The high severity CVSS score of 7.3 indicates significant risk, yet the EPSS score of less than 1% shows that exploitation is currently unlikely. Because the flaw requires authenticated access, it is not listed in the CISA KEV catalog. The attack vector is inferred to be authenticated web requests that inject script content into SharePoint pages, which is later rendered in the target browser.

Generated by OpenCVE AI on August 12, 2026 at 15:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft security update for SharePoint Server 2019 and Subscription Edition as listed on the Microsoft Security Response Center
  • Restrict page editing privileges to trusted users and review recent page modifications for unauthorized scripts
  • Enable a strict content security policy for SharePoint pages to block execution of injected XSS payloads

Generated by OpenCVE AI on August 12, 2026 at 15:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft sharepoint Server Subscription Edition
Vendors & Products Microsoft sharepoint Server Subscription Edition

Thu, 13 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:*

Wed, 12 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
Title Microsoft SharePoint Server Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft sharepoint Server
Microsoft sharepoint Server 2019
Weaknesses CWE-79
CPEs cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*
cpe:2.3:a:microsoft:sharepoint_server_2019:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft sharepoint Server
Microsoft sharepoint Server 2019
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N'}


Subscriptions

Microsoft Sharepoint Server Sharepoint Server 2019 Sharepoint Server Subscription Edition
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-31T20:06:22.419Z

Reserved: 2026-08-04T00:04:56.038Z

Link: CVE-2026-70355

cve-icon Vulnrichment

Updated: 2026-08-12T13:36:50.410Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:19:12.810

Modified: 2026-08-13T13:50:09.487

Link: CVE-2026-70355

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T12:45:16Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')