CVE-2026-69683: Microsoft Office SharePoint Information Disclosure Vulnerability
Published Sep 8, 2026
·Updated
Microsoft Office SharePoint Information Disclosure Vulnerability
Other sources
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
— Microsoft
Affected Software
3 affected componentsFixes available
Microsoft SharePoint
Microsoft SharePoint Server Subscription Edition<16.0.20326.20082
16.0.20326.20082
Microsoft SharePoint Server<16.0.20326.20082
Remediation
Event History
Sep 8, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·02:00 PM
Description
CVE Published
via MITRE·05:13 PM
Data Sourced
via MITRE·05:13 PM
DescriptionSeverity
Data Sourced
via NVD·06:19 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What level of access does an attacker need?
The attacker must be authorized, meaning exploitation requires at least low-level privileges in SharePoint. The vulnerability is exploitable over the network and does not require user interaction.
2
What is the potential impact of successful exploitation?
Successful exploitation can disclose information through server-side request forgery. The provided assessment indicates high confidentiality impact, with no indicated integrity or availability impact.
3
Which SharePoint products are identified as affected?
The listed affected software includes Microsoft SharePoint and Microsoft SharePoint Server Subscription Edition.