CVE-2026-69690: Microsoft Office SharePoint Spoofing Vulnerability
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Other sources
Microsoft Office SharePoint Spoofing Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.20326.20090Patch KB5002908
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The attacker must already be authorized to use the affected SharePoint environment. Exploitation is performed over the network and requires user interaction.
What is the likely impact if exploitation succeeds?
The vulnerability enables spoofing and is associated with cross-site scripting caused by improper neutralization of input during web page generation. The provided severity vector indicates low potential impact to confidentiality and integrity, with no availability impact.
Which products are identified as affected?
The affected software listed is Microsoft Office SharePoint and Microsoft SharePoint Server Subscription Edition.