Junglewise Threat Intelligence

CVE-2026-47638: Microsoft Office SharePoint cross-site scripting

CVE-2026-47638 · Severity: medium · CVSS 4.6 · Published 2026-06-09

Technologies: Microsoft Office SharePoint, Microsoft SharePoint. Vendors: Microsoft.

Executive brief

Microsoft Office SharePoint, a widely used collaboration and document management platform, is affected by a security vulnerability that could allow an attacker to perform spoofing attacks. An authorized user with basic access could trick other users into executing malicious scripts within their web browser session. This could lead to unauthorized actions being performed on behalf of the victim or the theft of sensitive information handled within the SharePoint environment.

Technical details

A cross-site scripting (XSS) vulnerability exists in Microsoft Office SharePoint due to improper neutralization of input during web page generation (CWE-79). An attacker with low-privileged credentials (PR:L) can exploit this over the network by injecting malicious scripts into SharePoint pages. Successful exploitation requires a victim to interact with a malicious link or page (UI:R). This allows the attacker to perform spoofing, potentially leading to unauthorized data access or session hijacking within the context of the affected user's browser. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Office SharePoint

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References

Related threats