CVE-2026-69464: Microsoft Office SharePoint Elevation of Privilege Vulnerability
Published Sep 8, 2026
·Updated
Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
Other sources
Microsoft Office SharePoint Elevation of Privilege Vulnerability
— Microsoft
Affected Software
2 affected componentsFixes available
Microsoft SharePoint Server Subscription Edition<16.0.20326.20090
16.0.20326.20090
Microsoft SharePoint Server<16.0.20326.20090
Remediation
Event History
Sep 8, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·02:00 PM
Affected Software
Updated
via Microsoft·02:00 PM
Description
CVE Published
via MITRE·05:17 PM
Data Sourced
via MITRE·05:17 PM
DescriptionSeverity
Data Sourced
via NVD·06:19 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
Who can exploit this vulnerability?
An attacker must be authorized to access the affected SharePoint environment and can exploit it over the network. The provided information does not indicate that unauthenticated attackers can exploit it.
2
What impact could successful exploitation have?
Successful exploitation allows execution with unnecessary privileges, enabling the attacker to elevate privileges. The supplied severity vector indicates high impacts to confidentiality, integrity, and availability.
3
Is SharePoint Server Subscription Edition affected?
Yes. Microsoft SharePoint Server Subscription Edition is identified as the affected software in the provided data.