Executive brief
Microsoft SharePoint is a widely used collaboration and document management platform for businesses. A vulnerability in how the system handles user input could allow an authorized user to perform a spoofing attack against other users. This could lead to unauthorized actions being performed in the context of a victim's session or the display of fraudulent information.
Technical details
A cross-site scripting (XSS) vulnerability exists in Microsoft SharePoint due to improper neutralization of input during web page generation (CWE-79). An authenticated attacker with low privileges can exploit this by sending a specially crafted request to a vulnerable SharePoint server. Successful exploitation requires a victim to interact with a malicious link or page, allowing the attacker to execute script in the victim's browser session. This can result in unauthorized information disclosure or data modification within the scope of the victim's permissions. The vulnerability affects SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition.
Affected products
- Microsoft SharePoint Enterprise Server 2016 < 16.0.5561.1001
- Microsoft SharePoint Server 2019 < 16.0.10417.20175
- Microsoft SharePoint Server Subscription Edition < 16.0.19725.20434
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory: Microsoft released security updates for affected versions.