Junglewise Threat Intelligence

CVE-2026-69282: Microsoft Office SharePoint improper access control

CVE-2026-69282 · Severity: high · CVSS 8.8 · Published 2026-09-08

Technologies: Microsoft Office SharePoint, Microsoft SharePoint Server. Vendors: Microsoft.

Executive brief

Microsoft Office SharePoint contains an access control vulnerability that allows an authorized user to execute arbitrary code remotely over the network. This could enable a compromised or malicious user account to take control of SharePoint servers and potentially access sensitive documents and data stored within the platform.

Technical details

An improper access control vulnerability in Microsoft Office SharePoint allows an authorized attacker to execute arbitrary code over the network. The vulnerability requires an attacker to be authenticated to the system but does not appear to require additional user interaction. Successful exploitation could result in remote code execution with the privileges of the SharePoint service account, potentially leading to full compromise of affected SharePoint instances and stored data.

Affected products

  • Microsoft Office SharePoint

Timeline

  • 2026-09-08: disclosed

References

Related threats