Junglewise Threat Intelligence

CVE-2026-47639: Microsoft Office SharePoint cross-site scripting

CVE-2026-47639 · Severity: medium · CVSS 5.4 · Published 2026-06-09

Technologies: Microsoft Office SharePoint, Microsoft SharePoint. Vendors: Microsoft.

Executive brief

Microsoft Office SharePoint, a widely used collaboration and document management platform, is vulnerable to a security flaw that allows attackers to perform spoofing. By tricking a user into interacting with a malicious link or page, an attacker can execute unauthorized scripts in the user's browser session. This could lead to the theft of sensitive information or unauthorized actions performed on behalf of the user within the SharePoint environment.

Technical details

A cross-site scripting (XSS) vulnerability exists in Microsoft Office SharePoint due to improper neutralization of input during web page generation (CWE-79). An attacker can exploit this by sending a specially crafted request to a SharePoint server, which requires a user to interact with a malicious link or page (User Interaction: Required). Successful exploitation allows the attacker to perform spoofing and execute arbitrary script code in the context of the victim's browser session. The vulnerability is reachable over the network and has been assigned a CVSS 3.1 base score of 5.4.

Affected products

  • Microsoft Office SharePoint

Timeline

  • 2026-06-09: disclosed: Initial publication of the vulnerability advisory.
  • 2026-06-09: advisory: Microsoft released security update information.

References

Related threats