Executive brief
Microsoft SharePoint, a widely used collaboration and document management platform, is affected by a security vulnerability that could allow an attacker to perform spoofing attacks. An authorized user could exploit this flaw to execute malicious scripts in another user's browser session, potentially leading to unauthorized actions or the theft of sensitive information. This could compromise the integrity of internal communications and data handled within the SharePoint environment.
Technical details
A cross-site scripting (XSS) vulnerability (CWE-79) exists in Microsoft SharePoint due to improper neutralization of input during web page generation. An authenticated attacker with low privileges can exploit this over the network by convincing a victim to interact with a specially crafted link or page. Successful exploitation allows the attacker to execute arbitrary script in the context of the victim's browser, enabling spoofing or unauthorized data access. The vulnerability affects SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition; patches are available through Microsoft's standard update channels.
Affected products
- Microsoft SharePoint Enterprise Server 2016 < 16.0.5561.1001
- Microsoft SharePoint Server 2019 < 16.0.10417.20175
- Microsoft SharePoint Server Subscription Edition < 16.0.19725.20434
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory