Junglewise Threat Intelligence

CVE-2026-45464: Microsoft Office SharePoint cross-site scripting

CVE-2026-45464 · Severity: medium · CVSS 5.4 · Published 2026-06-09

Technologies: Microsoft Office SharePoint, Microsoft SharePoint. Vendors: Microsoft.

Executive brief

Microsoft Office SharePoint, a widely used collaboration and document management platform, contains a security vulnerability that could allow an attacker to perform spoofing. By tricking a user into interacting with a malicious link or page, an attacker can execute unauthorized scripts in the user's browser session. This could lead to the theft of sensitive information or unauthorized actions performed on behalf of the user within the SharePoint environment.

Technical details

A cross-site scripting (XSS) vulnerability exists in Microsoft Office SharePoint due to improper neutralization of input during web page generation (CWE-79). The vulnerability allows a remote attacker to perform spoofing over a network. According to the CVSS vector, the attack requires user interaction (UI:R) but no prior privileges (PR:N). An attacker who successfully exploits this vulnerability could execute arbitrary script code in the context of the victim's browser, potentially leading to session hijacking or unauthorized data access. Microsoft has released information regarding this vulnerability in their Security Update Guide.

Affected products

  • Microsoft Office SharePoint

Timeline

  • 2026-06-09: disclosed: Initial publication of the CVE record and Microsoft advisory.

References

Related threats