Junglewise Threat Intelligence

CVE-2026-55020: Microsoft SharePoint cross-site scripting vulnerability

CVE-2026-55020 · Severity: medium · CVSS 4.6 · Published 2026-07-14

Technologies: Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server Subscription Edition, Microsoft SharePoint Server 2019. Vendors: Microsoft.

Executive brief

Microsoft SharePoint, a widely used platform for document management and team collaboration, is affected by a security flaw that could allow an attacker to perform spoofing. An authorized user could trick another person into interacting with malicious content, potentially leading to unauthorized actions or the theft of sensitive information within the SharePoint environment. This could compromise the integrity of internal communications and data.

Technical details

A cross-site scripting (XSS) vulnerability exists in Microsoft Office SharePoint due to improper neutralization of input during web page generation. An authenticated attacker with low privileges can exploit this flaw by sending a specially crafted request to a vulnerable SharePoint server. Successful exploitation requires a victim to interact with a malicious link or page, allowing the attacker to execute scripts in the context of the victim's browser session. This can lead to spoofing, session hijacking, or unauthorized data access. Microsoft has released security updates to address this issue across affected versions of SharePoint Server.

Affected products

  • Microsoft SharePoint Enterprise Server 2016 16.0.0 to 16.0.5561.1001
  • Microsoft SharePoint Server 2019 16.0.0 to 16.0.10417.20175
  • Microsoft SharePoint Server Subscription Edition 16.0.0 to 16.0.19725.20434

Timeline

  • 2026-07-14: advisory: Microsoft released the security advisory and patches.
  • 2026-07-14: disclosed: CVE-2026-55020 was published to the NVD.

References

Related threats