CVE-2026-70326: Microsoft SharePoint Server Elevation of Privilege Vulnerability
Published Aug 11, 2026
·Updated
Microsoft SharePoint Server Elevation of Privilege Vulnerability
Other sources
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
— Microsoft
Affected Software
3 affected componentsFixes available
Microsoft SharePoint Server
Microsoft SharePoint Server Subscription Edition<16.0.19725.20522
16.0.19725.20522
Microsoft SharePoint Server<16.0.19725.20522
Remediation
Event History
Aug 11, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·02:00 PM
Affected Software
Updated
via Microsoft·02:00 PM
Description
CVE Published
via MITRE·05:07 PM
Data Sourced
via MITRE·05:07 PM
DescriptionSeverity
Data Sourced
via NVD·05:19 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-70326?
The severity of CVE-2026-70326 is rated high with a score of 8.8.
2
How do I fix CVE-2026-70326?
To fix CVE-2026-70326, apply the patch provided by Microsoft for affected versions of SharePoint Server.
3
What systems are affected by CVE-2026-70326?
CVE-2026-70326 affects Microsoft SharePoint Server and Microsoft SharePoint Server Subscription Edition.
4
What type of vulnerability is CVE-2026-70326?
CVE-2026-70326 is a server-side request forgery (SSRF) vulnerability that allows privilege escalation.
5
Can CVE-2026-70326 be exploited remotely?
Yes, CVE-2026-70326 can be exploited remotely by an authorized attacker.