Junglewise Threat Intelligence

CVE-2026-69273: Microsoft Office SharePoint improper access control remote code execution

CVE-2026-69273 · Severity: high · CVSS 8.8 · Published 2026-09-08

Technologies: Microsoft Office SharePoint, Microsoft SharePoint Server. Vendors: Microsoft.

Executive brief

Microsoft Office SharePoint contains an improper access control vulnerability that allows authorized users to execute arbitrary code across the network. This could enable a malicious insider or compromised account to take control of SharePoint servers and access sensitive business documents, potentially affecting collaboration infrastructure and data confidentiality.

Technical details

The vulnerability exists in Microsoft Office SharePoint due to improper access control checks that fail to adequately restrict code execution capabilities. An attacker with valid authorization credentials can exploit this flaw to execute arbitrary code on the SharePoint server over the network. The attack requires the attacker to be authenticated to the system. Successful exploitation allows remote code execution (RCE) with the privileges of the affected service, potentially leading to full system compromise. A security update addressing this issue is available from Microsoft.

Affected products

  • Microsoft Office SharePoint

Timeline

  • 2026-09-08: disclosed

References

Related threats