Executive brief
Microsoft SharePoint, a widely used collaboration and document management platform, is affected by a security flaw that could allow an attacker to impersonate legitimate users. By tricking a user into clicking a malicious link, an attacker with basic access to the network could steal sensitive information or perform unauthorized actions on behalf of the victim. This could lead to data breaches or unauthorized changes to corporate documents and internal sites.
Technical details
A cross-site scripting (XSS) vulnerability exists in Microsoft SharePoint due to improper neutralization of input during web page generation. An authenticated attacker with low privileges can exploit this by sending a specially crafted request to a vulnerable SharePoint server. Successful exploitation requires a victim to interact with a malicious link or page, allowing the attacker to execute arbitrary script in the context of the victim's browser session. This can result in the theft of session tokens, unauthorized data access, or spoofing of user actions. Microsoft has released security updates for SharePoint Enterprise Server 2016, Server 2019, and Subscription Edition to address this issue.
Affected products
- Microsoft SharePoint Enterprise Server 2016 16.0.0 to 16.0.5561.1001
- Microsoft SharePoint Server 2019 16.0.0 to 16.0.10417.20175
- Microsoft SharePoint Server Subscription Edition 16.0.0 to 16.0.19725.20434
Timeline
- 2026-07-14: advisory: Initial publication by Microsoft and NVD