Executive brief
Microsoft Office SharePoint is a widely-used enterprise collaboration and document management platform. An authorized attacker can exploit a cross-site scripting (XSS) vulnerability to inject malicious scripts into web pages, enabling account spoofing and potential credential theft or malware delivery to other users accessing the affected SharePoint site.
Technical details
The vulnerability is a reflected or stored cross-site scripting (XSS) flaw in SharePoint's web page generation logic, where user-supplied input is not properly neutralized before being rendered in HTML. An attacker who has already been authenticated to SharePoint can craft a malicious URL or inject code through a SharePoint interface element to execute arbitrary JavaScript in the context of other users' browsers. This allows for session hijacking, credential theft, and spoofing attacks. A patch is available from Microsoft as indicated by the CVE publication and security update guide.
Affected products
- Microsoft Office SharePoint
Timeline
- 2026-08-11: disclosed