Executive brief
Microsoft SharePoint, a widely used platform for document management and team collaboration, is affected by a security flaw that could allow an attacker to perform spoofing attacks. By tricking a user into interacting with a malicious link or page, an attacker with basic user permissions could execute unauthorized scripts in the victim's browser. This could lead to the unauthorized viewing of sensitive documents or the performance of actions on behalf of the victim within the SharePoint environment.
Technical details
A cross-site scripting (XSS) vulnerability (CWE-79) exists in Microsoft Office SharePoint due to improper neutralization of input during web page generation. An attacker with low-level authenticated permissions (PR:L) can exploit this by sending a specially crafted request to a vulnerable SharePoint server. Successful exploitation requires a victim to interact with a malicious link or page (UI:R). This allows the attacker to execute arbitrary script in the context of the victim's browser session, potentially leading to information disclosure or unauthorized actions. Microsoft has released security updates for SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition to address this issue.
Affected products
- Microsoft SharePoint Enterprise Server 2016 < 16.0.5561.1001
- Microsoft SharePoint Server 2019 < 16.0.10417.20175
- Microsoft SharePoint Server Subscription Edition < 16.0.19725.20434
Timeline
- 2026-07-16: disclosed
- 2026-07-16: advisory