CVE-2026-69465: Microsoft Office SharePoint Remote Code Execution Vulnerability
Microsoft Office SharePoint Remote Code Execution Vulnerability
Other sources
Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.20326.20074Patch KB5002908
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker must be authorized to access the affected Microsoft SharePoint Server Subscription Edition instance. Exploitation can be performed over the network and does not require user interaction.
What level of impact could successful exploitation have?
Successful exploitation can allow remote code execution. The provided severity metrics indicate high impact to confidentiality, integrity, and availability.
Are unauthenticated or default deployments affected?
The available information identifies an authorized attacker as the required privilege level. It does not state whether unauthenticated access or any particular default configuration is affected.