CVE-2026-70324: Microsoft SharePoint Elevation of Privilege Vulnerability
Microsoft SharePoint Elevation of Privilege Vulnerability
Other sources
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5565.1001Patch KB5002906 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.19725.20522Patch KB5002893 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.10417.20198Patch KB5002896
Event History
Frequently Asked Questions
What is the severity of CVE-2026-70324?
CVE-2026-70324 has a high severity rating of 8.8.
What is CVE-2026-70324 about?
CVE-2026-70324 describes a server-side request forgery vulnerability in Microsoft SharePoint that allows authorized attackers to elevate their privileges.
Which Microsoft SharePoint versions are affected by CVE-2026-70324?
CVE-2026-70324 impacts Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server Subscription Edition, and Microsoft SharePoint Server 2019.
How do I fix CVE-2026-70324?
To remediate CVE-2026-70324, apply the latest security updates from Microsoft for the affected SharePoint products.
What kind of attacks can CVE-2026-70324 facilitate?
CVE-2026-70324 can facilitate elevation of privilege attacks over a network for authorized users.