Junglewise Threat Intelligence

CVE-2026-56157: Microsoft SharePoint improper access control spoofing vulnerability

CVE-2026-56157 · Severity: medium · CVSS 5.4 · Published 2026-07-14

Executive brief

Microsoft SharePoint, a widely used collaboration and document management platform, contains a security flaw that could allow an authorized user to impersonate other users or services. While the attacker must already have basic access to the network, they could use this vulnerability to misrepresent their identity, potentially leading to unauthorized actions or data access. Organizations should apply the latest security updates from Microsoft to protect their internal communications and data integrity.

Technical details

A spoofing vulnerability exists in Microsoft SharePoint due to improper access control (CWE-284). An authenticated attacker with low privileges can exploit this flaw over the network without requiring user interaction. Successful exploitation allows the attacker to spoof identities or communications within the SharePoint environment, potentially compromising data integrity or confidentiality. The vulnerability affects SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft SharePoint Enterprise Server 2016 16.0.0 to 16.0.5561.1001
  • Microsoft SharePoint Server 2019 16.0.0 to 16.0.10417.20175
  • Microsoft SharePoint Server Subscription Edition 16.0.0 to 16.0.19725.20434

Timeline

  • 2026-07-14: advisory: Initial publication by Microsoft and NVD

References

Related threats