CVE-2026-20958: Microsoft SharePoint Information Disclosure Vulnerability
Microsoft SharePoint Information Disclosure Vulnerability
Other sources
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.10417.20083Patch KB5002825 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5535.1001Patch KB5002828 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.19127.20442Patch KB5002822
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20958?
CVE-2026-20958 has a high severity rating due to the potential for information disclosure through server-side request forgery.
How do I fix CVE-2026-20958?
To fix CVE-2026-20958, apply the appropriate security patches provided by Microsoft for your version of SharePoint Server.
What versions of SharePoint are affected by CVE-2026-20958?
CVE-2026-20958 affects Microsoft SharePoint Server 2019, SharePoint Server Subscription Edition, and SharePoint Enterprise Server 2016.
What are the potential impacts of CVE-2026-20958?
The potential impacts of CVE-2026-20958 include unauthorized information disclosure, which could lead to further exploits or data breaches.
Who is vulnerable to CVE-2026-20958?
Organizations using unpatched versions of Microsoft SharePoint Server 2019, SharePoint Server Subscription Edition, or SharePoint Enterprise Server 2016 may be vulnerable to CVE-2026-20958.