Junglewise Threat Intelligence

CVE-2026-45465: Microsoft Office SharePoint cross-site scripting

CVE-2026-45465 · Severity: medium · CVSS 5.4 · Published 2026-06-09

Technologies: Microsoft Office SharePoint, Microsoft SharePoint. Vendors: Microsoft.

Executive brief

Microsoft Office SharePoint, a widely used collaboration and document management platform, is affected by a security vulnerability that could allow an attacker to perform spoofing. By tricking a user into interacting with a malicious link or page, an attacker can execute unauthorized scripts in the context of the user's session. This could lead to unauthorized access to sensitive documents, data theft, or the performance of actions on behalf of the compromised user.

Technical details

A cross-site scripting (XSS) vulnerability exists in Microsoft Office SharePoint due to improper neutralization of input during web page generation (CWE-79). An attacker can exploit this by sending a specially crafted request to a vulnerable SharePoint instance. While the advisory mentions an 'authorized attacker' in the description, the CVSS vector (PR:N) suggests that no special privileges are required, though user interaction (UI:R) is necessary. Successful exploitation allows the attacker to execute arbitrary script code in the victim's browser session, potentially leading to information disclosure or session hijacking. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Office SharePoint

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References

Related threats