Executive brief
Microsoft SharePoint is a widely used platform for document management and team collaboration. A security vulnerability has been identified that allows an authorized user to execute malicious commands on the server. This could lead to a total compromise of the SharePoint environment, including the theft of sensitive corporate data or the disruption of business operations.
Technical details
A remote code execution vulnerability exists in Microsoft Office SharePoint due to the unsafe deserialization of untrusted data. An attacker with site member permissions (low privilege) can exploit this by sending a specially crafted network request to a vulnerable SharePoint server. Successful exploitation requires some user interaction, as indicated by the CVSS vector. If successful, the attacker can execute arbitrary OS commands in the context of the SharePoint service account, potentially leading to full system compromise. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Office SharePoint
Timeline
- 2026-06-01: disclosed
- 2026-06-01: advisory