CVE-2026-69417: Microsoft Office SharePoint Spoofing Vulnerability
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Other sources
Microsoft Office SharePoint Spoofing Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.20326.20090Patch KB5002908
Event History
Frequently Asked Questions
What level of access and interaction are required for exploitation?
An attacker must be authorized, so they need valid access to the affected SharePoint environment. Exploitation is network-accessible and requires a user to interact with attacker-controlled content.
What is the likely security impact?
The vulnerability is an input-neutralization issue during web page generation, classified as cross-site scripting. It allows an authorized attacker to perform spoofing and is rated high severity with high confidentiality and integrity impact.
Which product is identified as affected?
The affected software listed is Microsoft SharePoint Server Subscription Edition.