Executive brief
Microsoft SharePoint is a widely used collaboration and document management platform. A vulnerability in this system allows an authenticated user to perform a cross-site scripting (XSS) attack, which could be used to spoof content or trick other users into performing unintended actions. This could lead to unauthorized access to sensitive information or the manipulation of web content within the corporate environment.
Technical details
A cross-site scripting (XSS) vulnerability exists in Microsoft SharePoint due to improper neutralization of input during web page generation (CWE-79). An authenticated attacker with low privileges can exploit this vulnerability over the network, though it requires interaction from a victim (user interaction). Successful exploitation allows the attacker to perform spoofing and potentially gain unauthorized access to data or execute scripts in the context of the victim's browser session. The vulnerability affects SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition.
Affected products
- Microsoft SharePoint Enterprise Server 2016 < 16.0.5561.1001
- Microsoft SharePoint Server 2019 < 16.0.10417.20175
- Microsoft SharePoint Server Subscription Edition < 16.0.19725.20434
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory