Executive brief
Microsoft SharePoint is a widely used collaboration and document management platform for businesses. A vulnerability has been identified that allows an authorized user to manipulate file paths, potentially leading to spoofing or unauthorized access to sensitive information. This could allow an internal attacker to misrepresent data or gain access to files they are not intended to see, impacting the integrity and confidentiality of corporate data.
Technical details
A vulnerability exists in Microsoft SharePoint (Enterprise Server 2016, Server 2019, and Subscription Edition) due to improper validation of user-supplied input used in file names or paths (CWE-73). An authenticated attacker with low privileges can exploit this over a network by providing specially crafted input to the server. Successful exploitation allows the attacker to perform spoofing or potentially access unauthorized files, leading to a high impact on confidentiality. The vulnerability is addressed in the July 2026 security updates for the affected SharePoint versions.
Affected products
- Microsoft SharePoint Enterprise Server 2016 < 16.0.5561.1001
- Microsoft SharePoint Server 2019 < 16.0.10417.20175
- Microsoft SharePoint Server Subscription Edition < 16.0.19725.20434
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory