Executive brief
Microsoft SharePoint, a widely used platform for document management and team collaboration, is affected by a security vulnerability that could allow an authorized user to execute malicious code on the server. An attacker with basic user permissions could exploit this flaw to gain full control over the SharePoint environment, potentially leading to the theft of sensitive corporate data or disruption of business operations. Organizations should apply the available security updates from Microsoft to protect their internal document repositories.
Technical details
A deserialization vulnerability (CWE-502) exists in Microsoft SharePoint Server due to the improper handling of untrusted data. An attacker with Site Member permissions (low privilege) can exploit this by sending a specially crafted request to a vulnerable SharePoint instance. Successful exploitation requires some user interaction and allows the attacker to achieve remote code execution (RCE) in the context of the SharePoint service account. The vulnerability affects SharePoint Server 2016, 2019, and Subscription Edition; Microsoft has released security updates to address this issue.
Affected products
- Microsoft SharePoint Server 2016 Enterprise Edition
- Microsoft SharePoint Server 2019
- Microsoft SharePoint Server Subscription Edition up to (excluding) 16.0.19725.20280
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory: MSRC advisory published