CVE-2026-69409: Microsoft Office SharePoint Information Disclosure Vulnerability
Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
Other sources
Microsoft Office SharePoint Information Disclosure Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.20326.20090Patch KB5002908
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker must be authorized to access the affected SharePoint Server Subscription Edition environment. The issue is exploitable over a network and does not require user interaction.
What is the impact if exploitation succeeds?
Successful exploitation allows disclosure of information. The supplied severity metrics indicate high confidentiality impact, with no indicated integrity or availability impact.
Does exploitation require a complex attack chain?
The available metrics classify attack complexity as low and privileges required as low. This indicates an authenticated attacker with limited privileges may be able to exploit the issue without complex conditions.