CVE-2026-69716: Microsoft Office SharePoint Elevation of Privilege Vulnerability
Published Sep 8, 2026
·Updated
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
Other sources
Microsoft Office SharePoint Elevation of Privilege Vulnerability
— Microsoft
Affected Software
2 affected componentsFixes available
Microsoft SharePoint Server Subscription Edition<16.0.20326.20094
16.0.20326.20094
Microsoft SharePoint Server<16.0.20326.20094
Remediation
Event History
Sep 8, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·02:00 PM
Affected Software
Updated
via Microsoft·02:00 PM
Description
CVE Published
via MITRE·05:13 PM
Data Sourced
via MITRE·05:13 PM
DescriptionSeverity
Data Sourced
via NVD·06:19 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
Who can exploit this issue?
An attacker needs authorized access with low privileges and network access to the affected SharePoint server. No user interaction is required.
2
Which deployments are identified as affected?
The affected software listed is Microsoft SharePoint Server Subscription Edition. The provided data does not identify other SharePoint versions or products.
3
What could a successful exploit allow?
A successful exploit can elevate the attacker's privileges. The supplied severity vector rates confidentiality, integrity, and availability impact as high.