Junglewise Threat Intelligence

CVE-2026-47298: Microsoft Office SharePoint improper authorization code execution

CVE-2026-47298 · Severity: high · CVSS 8 · Published 2026-06-09

Technologies: Microsoft Office SharePoint, Microsoft SharePoint. Vendors: Microsoft.

Executive brief

Microsoft Office SharePoint, a widely used platform for document management and team collaboration, contains a security flaw that could allow an authorized user to run unauthorized code on the server. An attacker with basic user permissions could exploit this vulnerability over the network, potentially leading to full system compromise, data theft, or service disruption. This requires some level of user interaction to be successful.

Technical details

A remote code execution vulnerability exists in Microsoft Office SharePoint due to improper authorization (CWE-285). An attacker must be authenticated to the target environment with at least low-privileged user permissions to initiate the attack. The exploit is delivered over the network and requires a degree of user interaction (UI:R) to succeed. If successfully exploited, the attacker can achieve high impact across confidentiality, integrity, and availability by executing arbitrary code in the context of the SharePoint server. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Office SharePoint

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References

Related threats