CVE-2026-55020: Microsoft SharePoint Server Spoofing Vulnerability
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Other sources
Microsoft SharePoint Server Spoofing Vulnerability
— Microsoft
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-55020?
The severity of CVE-2026-55020 is medium with a score of 5.4.
How do I fix CVE-2026-55020?
To fix CVE-2026-55020, apply the available patch from Microsoft for your SharePoint Server version.
What systems are affected by CVE-2026-55020?
CVE-2026-55020 affects Microsoft SharePoint Server, including versions 2019 and Subscription Edition, as well as Microsoft SharePoint Enterprise Server 2016.
What type of vulnerability is CVE-2026-55020?
CVE-2026-55020 is classified as a spoofing vulnerability due to improper input neutralization in SharePoint.
What kind of threat does CVE-2026-55020 pose?
CVE-2026-55020 allows an authorized attacker to perform spoofing over a network, potentially leading to unauthorized access or data manipulation.