Junglewise Threat Intelligence

CVE-2026-58277: Microsoft SharePoint improper authorization privilege escalation

CVE-2026-58277 · Severity: high · CVSS 8.8 · Published 2026-07-14

Executive brief

Microsoft SharePoint, a widely used platform for document management and team collaboration, contains a security flaw that allows an existing user to gain higher-level administrative permissions. An attacker with basic access to the corporate network could exploit this to access sensitive documents, modify site content, or disrupt business operations. Organizations should apply the latest security updates from Microsoft to prevent unauthorized access to their internal data.

Technical details

An improper authorization vulnerability (CWE-285) exists in Microsoft SharePoint Server 2019 and SharePoint Enterprise Server 2016. The flaw allows a remote attacker with low-privileged user credentials to bypass authorization checks and elevate their privileges within the SharePoint environment. The attack is carried out over the network and does not require user interaction. Successful exploitation grants the attacker high-level access, potentially leading to a full compromise of confidentiality, integrity, and availability of the SharePoint site data. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft SharePoint Enterprise Server 2016 16.0.0 to 16.0.5561.1001
  • Microsoft SharePoint Server 2019 16.0.0 to 16.0.10417.20175

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats