Executive brief
Microsoft Office SharePoint contains an improper access control vulnerability that allows an authorized attacker to execute arbitrary code over a network. This could enable an insider or compromised user to take control of a SharePoint environment, access sensitive documents, and potentially pivot to other systems within the organization.
Technical details
The vulnerability is an improper access control flaw in Microsoft Office SharePoint that permits an authorized attacker to execute code remotely over a network. The vulnerability requires the attacker to already have valid authentication credentials to the SharePoint environment. Successful exploitation allows remote code execution, enabling an attacker with legitimate access to compromise the SharePoint server and the data it hosts. Microsoft has released a security patch to address this issue.
Affected products
- Microsoft Office SharePoint
Timeline
- 2026-09-08: disclosed