Junglewise Threat Intelligence

CVE-2026-69268: Microsoft Office SharePoint improper access control

CVE-2026-69268 · Severity: high · CVSS 8.8 · Published 2026-09-08

Technologies: Microsoft Office SharePoint, Microsoft SharePoint Server. Vendors: Microsoft.

Executive brief

Microsoft Office SharePoint contains an improper access control vulnerability that allows an authorized attacker to execute arbitrary code over a network. This could enable an insider or compromised user to take control of a SharePoint environment, access sensitive documents, and potentially pivot to other systems within the organization.

Technical details

The vulnerability is an improper access control flaw in Microsoft Office SharePoint that permits an authorized attacker to execute code remotely over a network. The vulnerability requires the attacker to already have valid authentication credentials to the SharePoint environment. Successful exploitation allows remote code execution, enabling an attacker with legitimate access to compromise the SharePoint server and the data it hosts. Microsoft has released a security patch to address this issue.

Affected products

  • Microsoft Office SharePoint

Timeline

  • 2026-09-08: disclosed

References

Related threats