Executive brief
Microsoft Office SharePoint is a widely-used platform for document management and team collaboration in enterprise environments. This vulnerability allows an attacker with valid network credentials to bypass authentication controls on a critical function, potentially gaining elevated privileges and compromising the confidentiality and integrity of sensitive business documents and data stored in SharePoint.
Technical details
This vulnerability involves missing authentication for a critical function in Microsoft Office SharePoint. An authorized attacker can exploit this authentication bypass to elevate their privileges within the system. The attack vector is network-based and requires valid credentials or network access. Successful exploitation allows privilege escalation within SharePoint, potentially granting access to sensitive data or administrative capabilities. A patch is expected from Microsoft via their Security Update Guide.
Affected products
- Microsoft Office SharePoint
Timeline
- 2026-08-11: disclosed