Junglewise Threat Intelligence

CVE-2026-45479: Microsoft Office SharePoint Cross-Site Scripting

CVE-2026-45479 · Severity: medium · CVSS 4.6 · Published 2026-06-09

Technologies: Microsoft Office SharePoint, Microsoft SharePoint. Vendors: Microsoft.

Executive brief

Microsoft Office SharePoint, a widely used platform for document management and team collaboration, is affected by a security vulnerability that could allow an attacker to perform spoofing attacks. By tricking a user into interacting with a malicious link or page, an attacker with basic user permissions could execute unauthorized scripts in the victim's browser. This could lead to the unauthorized access of sensitive information or the performance of actions on behalf of the user within the SharePoint environment.

Technical details

A stored or reflected cross-site scripting (XSS) vulnerability exists in Microsoft Office SharePoint due to improper neutralization of user-supplied input during web page generation. An attacker with low-level authenticated permissions (PR:L) can exploit this over the network by injecting malicious scripts. Successful exploitation requires a legitimate user to interact with a crafted link or page (UI:R). This allows the attacker to execute arbitrary script code in the context of the victim's browser session, potentially leading to session hijacking or unauthorized data disclosure. Microsoft has released security updates to address this issue via the MSRC update guide.

Affected products

  • Microsoft Office SharePoint

Timeline

  • 2026-06-09: advisory: Initial disclosure by Microsoft and NVD.

References

Related threats