Executive brief
Microsoft Office SharePoint contains an access control vulnerability that allows an authorized user to execute arbitrary code remotely over the network. This could enable a compromised or malicious user account to take control of SharePoint servers and potentially access sensitive documents and data stored within the platform.
Technical details
An improper access control vulnerability in Microsoft Office SharePoint allows an authorized attacker to execute arbitrary code over the network. The vulnerability requires an attacker to be authenticated to the system but does not appear to require additional user interaction. Successful exploitation could result in remote code execution with the privileges of the SharePoint service account, potentially leading to full compromise of affected SharePoint instances and stored data.
Affected products
- Microsoft Office SharePoint
Timeline
- 2026-09-08: disclosed