Junglewise Threat Intelligence

CVE-2026-55126: Microsoft SharePoint cross-site scripting vulnerability

CVE-2026-55126 · Severity: high · CVSS 7.3 · Published 2026-07-14

Technologies: Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server Subscription Edition, Microsoft SharePoint Server 2019. Vendors: Microsoft.

Executive brief

Microsoft SharePoint, a widely used collaboration and document management platform, is vulnerable to a security flaw that allows authenticated users to perform spoofing attacks. By tricking another user into interacting with a malicious link or page, an attacker could potentially steal sensitive information or perform actions on behalf of that user. This could lead to unauthorized access to corporate documents or the compromise of user accounts within the organization.

Technical details

A cross-site scripting (XSS) vulnerability exists in Microsoft SharePoint due to improper neutralization of input during web page generation (CWE-79). An authenticated attacker with low privileges can exploit this vulnerability by sending a specially crafted request to a vulnerable SharePoint server. Successful exploitation requires a victim to interact with a malicious link or page (User Interaction: Required). This allows the attacker to execute arbitrary script in the context of the victim's browser, potentially leading to session hijacking, data theft, or unauthorized modifications. Microsoft has released security updates to address this issue across affected versions of SharePoint Server.

Affected products

  • Microsoft SharePoint Enterprise Server 2016 < 16.0.5561.1001
  • Microsoft SharePoint Server 2019 < 16.0.10417.20175
  • Microsoft SharePoint Server Subscription Edition < 16.0.19725.20434

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats