Executive brief
Microsoft SharePoint Server, a widely used platform for document management and team collaboration, is vulnerable to a security flaw that allows remote code execution. An attacker with basic user permissions can exploit this vulnerability to run malicious commands on the server. This could lead to a total compromise of the server, including the theft of sensitive corporate data, service disruption, or further lateral movement within the organization's network.
Technical details
A deserialization vulnerability (CWE-502) exists in Microsoft SharePoint Server due to the improper handling of untrusted data. An authenticated attacker with Site Owner permissions or higher (though CVSS indicates Low Privileges) can exploit this by sending a specially crafted network request to a vulnerable SharePoint instance. Successful exploitation allows the attacker to execute arbitrary code in the context of the SharePoint service account. The vulnerability affects SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition. Microsoft has released security updates to address this issue.
Affected products
- Microsoft SharePoint Enterprise Server 2016 < 16.0.5552.1002
- Microsoft SharePoint Server 2019 < 16.0.10417.20128
- Microsoft SharePoint Server Subscription Edition < 16.0.19725.20280
Timeline
- 2026-05-22: disclosed: Initial NVD publication date
- 2026-06-17: other: Last modified date in NVD record
- 2026-07-01: advisory: Advisory publication date provided in report