Junglewise Threat Intelligence

CVE-2026-64897: Microsoft Office SharePoint cross-site scripting

CVE-2026-64897 · Severity: medium · CVSS 4.6 · Published 2026-08-11

Technologies: Microsoft Office SharePoint. Vendors: Microsoft.

Executive brief

Microsoft Office SharePoint is a web-based platform used by organizations to store, organize, and share documents and information. This vulnerability allows an authorized user to inject malicious code into web pages, enabling them to spoof content or trick other users into performing unintended actions. While the attacker must already have legitimate access to the system, the attack requires no special technical expertise and could damage user trust or enable social engineering campaigns.

Technical details

This is a cross-site scripting (XSS) vulnerability arising from improper neutralization of user-supplied input during web page generation in Microsoft Office SharePoint. An authorized attacker can inject malicious JavaScript into the application, which is then reflected or stored and executed in the browsers of other users. The attack vector is network-based and requires the attacker to already have valid credentials; no elevation of privileges or special technical preconditions are needed. Successful exploitation allows spoofing of web content and potential session hijacking or credential theft. Microsoft has released a security patch to address this vulnerability.

Affected products

  • Microsoft Office SharePoint

Timeline

  • 2026-08-11: disclosed

References

Related threats