CVE-2026-69402: Microsoft Office SharePoint Spoofing Vulnerability
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Other sources
Microsoft Office SharePoint Spoofing Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.20326.20090Patch KB5002908
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The attacker must be authorized, meaning they need authenticated access to the affected SharePoint environment. Exploitation is possible over the network and requires low attack complexity.
Does successful exploitation require user interaction?
Yes. The vulnerability's vector specifies user interaction is required, so an attacker would need a user to interact with attacker-controlled content or a crafted page.
Which deployment is identified as affected?
The affected software listed is Microsoft SharePoint Server Subscription Edition. No information is provided about other SharePoint versions or configurations.