Junglewise Threat Intelligence

CVE-2026-47641: Microsoft Office SharePoint XSS in web page generation

CVE-2026-47641 · Severity: medium · CVSS 4.6 · Published 2026-06-09

Technologies: Microsoft Office SharePoint, Microsoft SharePoint. Vendors: Microsoft.

Executive brief

Microsoft Office SharePoint, a widely used collaboration and document management platform, contains a security vulnerability that could allow an attacker to perform spoofing attacks. By tricking a user into interacting with a malicious link or page, an attacker with basic user permissions could execute unauthorized scripts in the victim's browser. This could lead to the theft of sensitive information or unauthorized actions performed on behalf of the user within the SharePoint environment.

Technical details

A cross-site scripting (XSS) vulnerability exists in Microsoft Office SharePoint due to improper neutralization of input during web page generation. An authenticated attacker with low privileges (PR:L) can exploit this vulnerability by sending a specially crafted request to a SharePoint server. Successful exploitation requires a victim to interact with a malicious link or page (UI:R). The vulnerability allows the attacker to execute arbitrary script in the context of the victim's browser, potentially leading to information disclosure or unauthorized data modification. Microsoft has classified this as a spoofing vulnerability with a CVSS 3.1 base score of 4.6.

Affected products

  • Microsoft Office SharePoint

Timeline

  • 2026-06-09: advisory: Initial advisory published by Microsoft and NVD.

References

Related threats