CVE-2026-69615: Microsoft Office SharePoint Spoofing Vulnerability
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Other sources
Microsoft Office SharePoint Spoofing Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.20326.20090Patch KB5002908
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The attacker must already be authorized in SharePoint. Exploitation is performed over the network and also requires user interaction.
What is the likely impact if the vulnerability is exploited?
The stated impact is spoofing. The supplied vector also indicates limited confidentiality and integrity impact, with no availability impact.
Is Microsoft SharePoint Server Subscription Edition affected?
The affected software listed is Microsoft SharePoint Server Subscription Edition. No affected build numbers, update identifiers, or configuration prerequisites are provided.