Executive brief
Microsoft Office SharePoint, a widely used platform for document management and team collaboration, is affected by a security vulnerability that could allow an attacker to perform spoofing attacks. By exploiting this flaw, an authorized user could execute malicious scripts in another user's browser session, potentially leading to unauthorized access to sensitive documents or the theft of login credentials. This could compromise the integrity of corporate data and disrupt internal operations.
Technical details
A cross-site scripting (XSS) vulnerability exists in Microsoft Office SharePoint due to improper neutralization of input during web page generation (CWE-79). An attacker with basic user permissions (PR:L) can exploit this by injecting malicious scripts into SharePoint pages. The attack requires a victim to interact with a compromised page or link (UI:R). Successful exploitation allows the attacker to perform spoofing, hijack user sessions, or access sensitive information within the context of the victim's browser. The vulnerability is addressed in the June 2026 Microsoft security updates.
Affected products
- Microsoft Office SharePoint
Timeline
- 2026-06-09: advisory: Microsoft published the security advisory and NVD entry.
- 2026-06-09: patched: Security updates were made available via the Microsoft Update Guide.