Executive brief
Microsoft Office SharePoint, a widely used platform for document management and team collaboration, contains a security vulnerability that could allow an authorized user to access restricted files. By exploiting a flaw in how the system handles file paths, an attacker with basic login credentials could potentially view sensitive information or execute unauthorized commands. This poses a risk to the confidentiality of corporate data and the overall integrity of the SharePoint environment.
Technical details
A path traversal vulnerability (CWE-22) exists in Microsoft Office SharePoint due to improper limitation of pathnames to restricted directories. An attacker with low-privileged user credentials can exploit this flaw over a network by submitting specially crafted requests that navigate outside of intended folder structures. According to the advisory, this can lead to unauthorized code execution or sensitive data disclosure. The vulnerability is tracked as CVE-2026-45454 and has a CVSS 3.1 base score of 6.5, reflecting that while it requires authentication, it can be executed with low complexity and no user interaction.
Affected products
- Microsoft Office SharePoint
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory