CVE-2026-62837: Microsoft SharePoint Server Information Disclosure Vulnerability
Microsoft SharePoint Server Information Disclosure Vulnerability
Other sources
Relative path traversal in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.19725.20522Patch KB5002893 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5565.1001Patch KB5002906 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.10417.20198Patch KB5002896
Event History
Frequently Asked Questions
What is the severity of CVE-2026-62837?
The severity of CVE-2026-62837 is rated as medium with a score of 6.5.
How do I fix CVE-2026-62837?
To fix CVE-2026-62837, Microsoft recommends applying the latest security updates for Microsoft SharePoint Server.
What types of information can be disclosed due to CVE-2026-62837?
CVE-2026-62837 allows an authorized attacker to disclose sensitive information over a network through a relative path traversal vulnerability.
Which versions of Microsoft SharePoint are affected by CVE-2026-62837?
CVE-2026-62837 affects Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition, and Microsoft SharePoint Enterprise Server 2016.
What kind of attack does CVE-2026-62837 facilitate?
CVE-2026-62837 facilitates information disclosure attacks through a relative path traversal vulnerability in Microsoft SharePoint Server.