CVE-2026-69716: Microsoft Office SharePoint Elevation of Privilege Vulnerability
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
Other sources
Microsoft Office SharePoint Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.20326.20094Patch KB5002908
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs authorized access with low privileges and network access to the affected SharePoint server. No user interaction is required.
Which deployments are identified as affected?
The affected software listed is Microsoft SharePoint Server Subscription Edition. The provided data does not identify other SharePoint versions or products.
What could a successful exploit allow?
A successful exploit can elevate the attacker's privileges. The supplied severity vector rates confidentiality, integrity, and availability impact as high.