CVE-2026-62826: Microsoft SharePoint Server Spoofing Vulnerability
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Other sources
Microsoft SharePoint Server Spoofing Vulnerability
— Microsoft
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-62826?
CVE-2026-62826 has a severity rating of medium with a score of 4.6.
How do I fix CVE-2026-62826?
To fix CVE-2026-62826, apply the latest security patch provided by Microsoft for your SharePoint Server version.
What impact does CVE-2026-62826 have?
CVE-2026-62826 allows an attacker to perform spoofing attacks due to improper input neutralization in SharePoint.
Which software is affected by CVE-2026-62826?
CVE-2026-62826 affects Microsoft SharePoint Server, including the Subscription Edition, 2019, and Enterprise Server 2016.
Is user interaction required for CVE-2026-62826 exploitation?
Yes, user interaction is required for CVE-2026-62826 exploitation, as it involves an authorized attack.