Executive brief
Microsoft Office SharePoint contains a flaw in input validation that allows authenticated attackers to spoof content or identities over the network. This could enable fraudulent communications, unauthorized data access claims, or brand/user impersonation within enterprise collaboration environments.
Technical details
The vulnerability stems from improper input validation in Microsoft Office SharePoint. An authorized (authenticated) attacker can exploit this flaw over the network to perform spoofing attacks. The vulnerability requires valid credentials or prior authentication to the SharePoint environment. No evidence of active exploitation in the wild has been reported. Microsoft has released a security update to address this issue.
Affected products
- Microsoft Office SharePoint
Timeline
- 2026-08-11: disclosed
- patched: Security update released by Microsoft