Junglewise Threat Intelligence

CVE-2026-45453: Microsoft Office SharePoint cross-site scripting

CVE-2026-45453 · Severity: medium · CVSS 5.4 · Published 2026-06-09

Technologies: Microsoft Office SharePoint, Microsoft SharePoint. Vendors: Microsoft.

Executive brief

Microsoft Office SharePoint, a widely used collaboration and document management platform, is affected by a security vulnerability that could allow an attacker to perform spoofing. By tricking a user into interacting with a malicious link or page, an attacker can execute unauthorized scripts in the user's browser session. This could lead to the unauthorized access of sensitive information or the performance of actions on behalf of the user within the SharePoint environment.

Technical details

A cross-site scripting (XSS) vulnerability exists in Microsoft Office SharePoint due to improper neutralization of input during web page generation (CWE-79). An unauthenticated attacker can exploit this by sending a specially crafted request to a SharePoint server, though successful exploitation requires a user to interact with a malicious link (User Interaction: Required). If successful, the attacker can execute arbitrary script code in the context of the victim's browser, potentially leading to session hijacking or unauthorized data disclosure. The vulnerability is rated with a CVSS 3.1 base score of 5.4.

Affected products

  • Microsoft Office SharePoint

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References

Related threats