CVE-2026-69464: Microsoft Office SharePoint Elevation of Privilege Vulnerability
Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
Other sources
Microsoft Office SharePoint Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.20326.20090Patch KB5002908
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker must be authorized to access the affected SharePoint environment and can exploit it over the network. The provided information does not indicate that unauthenticated attackers can exploit it.
What impact could successful exploitation have?
Successful exploitation allows execution with unnecessary privileges, enabling the attacker to elevate privileges. The supplied severity vector indicates high impacts to confidentiality, integrity, and availability.
Is SharePoint Server Subscription Edition affected?
Yes. Microsoft SharePoint Server Subscription Edition is identified as the affected software in the provided data.