Executive brief
Microsoft SharePoint, a widely used collaboration and document management platform, is affected by a security vulnerability that could allow an attacker to impersonate legitimate users. By tricking a user into clicking a malicious link, an attacker with basic access to the network could execute unauthorized scripts in the victim's browser. This could lead to the theft of sensitive information or unauthorized actions performed on behalf of the user within the SharePoint environment.
Technical details
A cross-site scripting (XSS) vulnerability exists in Microsoft SharePoint due to improper neutralization of input during web page generation. An authenticated attacker with low privileges can exploit this vulnerability by sending a specially crafted request to a target SharePoint server. Successful exploitation requires a victim to interact with a malicious link or page, allowing the attacker to execute arbitrary script in the context of the victim's browser. This can result in session hijacking, unauthorized data access, or spoofing. The vulnerability affects SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition.
Affected products
- Microsoft SharePoint Enterprise Server 2016 16.0.0 to 16.0.5561.1001
- Microsoft SharePoint Server 2019 16.0.0 to 16.0.10417.20175
- Microsoft SharePoint Server Subscription Edition 16.0.0 to 16.0.19725.20434
Timeline
- 2026-07-14: disclosed: Initial publication of the CVE record by Microsoft.
- 2026-07-14: advisory: Microsoft released the Security Update Guide for this vulnerability.