Junglewise Threat Intelligence

CVE-2026-64902: Microsoft Office SharePoint stored cross-site scripting

CVE-2026-64902 · Severity: medium · CVSS 4.6 · Published 2026-08-11

Technologies: Microsoft Office SharePoint. Vendors: Microsoft.

Executive brief

Microsoft Office SharePoint is a collaboration platform used to manage documents and content across organizations. A cross-site scripting (XSS) vulnerability allows authorized users to inject malicious scripts that execute in other users' browsers, enabling account spoofing, credential theft, or unauthorized actions on behalf of legitimate users.

Technical details

This is a stored cross-site scripting (XSS) vulnerability in Microsoft Office SharePoint resulting from improper neutralization of user input during web page generation. An authorized attacker can inject malicious scripts through SharePoint's interface, which are then executed in the browsers of other users viewing the affected content. The vulnerability requires authentication to exploit and allows an attacker to perform spoofing attacks or redirect users to malicious sites. Patches are available from Microsoft.

Affected products

  • Microsoft Office SharePoint

Timeline

  • 2026-08-11: disclosed

References

Related threats