CVE-2026-69268: Microsoft Office SharePoint Remote Code Execution Vulnerability
Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Other sources
Microsoft Office SharePoint Remote Code Execution Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.20326.20090Patch KB5002908
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The attacker must be authorized, meaning they need valid access to the affected SharePoint environment. Exploitation can be performed over the network and does not require user interaction.
What is the potential impact if exploitation succeeds?
Successful exploitation can allow remote code execution. The supplied severity metrics indicate high impact to confidentiality, integrity, and availability.
Which products are identified as affected?
The affected software listed is Microsoft Office SharePoint and Microsoft SharePoint Server Subscription Edition.