Junglewise Threat Intelligence

CVE-2026-69402: Microsoft Office SharePoint cross-site scripting

CVE-2026-69402 · Severity: high · CVSS 7.3 · Published 2026-09-08

Technologies: Microsoft Office SharePoint, Microsoft SharePoint Server. Vendors: Microsoft.

Executive brief

Microsoft Office SharePoint is a widely-used enterprise collaboration platform for document management and team communication. A cross-site scripting (XSS) vulnerability allows authorized users to inject malicious scripts that execute in the browsers of other users, potentially leading to credential theft, session hijacking, or unauthorized actions performed on behalf of legitimate users.

Technical details

The vulnerability is an improper neutralization of user-supplied input during web page generation, resulting in reflected or stored cross-site scripting (XSS). An authorized attacker can inject malicious JavaScript into SharePoint pages, which will execute in the context of other users' browsers when they view the affected content. The vulnerability requires an authenticated attacker with privileges to create or modify content on the SharePoint site. Successful exploitation enables spoofing, credential harvesting, session hijacking, or malware distribution within the organization. Microsoft has released security patches to address this issue.

Affected products

  • Microsoft Office SharePoint

Timeline

  • 2026-09-08: disclosed
  • 2026-09-08: advisory

References

Related threats