Junglewise Threat Intelligence

CVE-2026-47640: Microsoft Office SharePoint cross-site scripting

CVE-2026-47640 · Severity: medium · CVSS 4.6 · Published 2026-06-09

Technologies: Microsoft Office SharePoint, Microsoft SharePoint. Vendors: Microsoft.

Executive brief

Microsoft Office SharePoint, a widely used collaboration and document management platform, is affected by a security vulnerability that allows for cross-site scripting. An authenticated attacker could use this flaw to perform spoofing attacks against other users on the network. This could lead to unauthorized actions being performed in the context of a victim's session or the theft of sensitive information through malicious web content.

Technical details

A cross-site scripting (XSS) vulnerability exists in Microsoft Office SharePoint due to improper neutralization of input during web page generation (CWE-79). An attacker with basic user permissions (PR:L) can exploit this over the network by injecting malicious scripts into SharePoint pages. Execution of the exploit requires a victim to interact with the affected page (UI:R). Successful exploitation allows the attacker to perform spoofing, potentially leading to session hijacking or unauthorized data access within the scope of the user's browser session. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Office SharePoint

Timeline

  • 2026-06-09: advisory: Microsoft published the security advisory.
  • 2026-06-09: disclosed

References

Related threats