Executive brief
Microsoft Office SharePoint is a collaboration and document management platform used by organizations to store and share business information. An authorization flaw in SharePoint allows an authenticated attacker to modify data or content they should not have access to, potentially compromising document integrity and confidentiality within an organization.
Technical details
An incorrect authorization vulnerability in Microsoft Office SharePoint fails to properly validate access controls before allowing data modification operations. The vulnerability requires an attacker to be authenticated to the system, but once authenticated, they can exploit the authorization bypass to perform unauthorized tampering on the network. The root cause lies in insufficient permission checks on sensitive operations. Exploitation allows an attacker to modify or delete content beyond their assigned permissions, and patches are available through Microsoft Security Updates.
Affected products
- Microsoft Office SharePoint
Timeline
- 2026-08-11: disclosed